Privacy Policy
Your privacy is important to us. It is our policy to respect your privacy regarding any information we may collect from you across our website, tryellie.com, and any other sites we own and operate.
1. Personal information
We only ask for personal information when we truly need it to provide the service to you. We collect it by fair and lawful means, with your knowledge and consent. We also let you know why we're collecting it and how it will be used.
We only retain collected information for as long as necessary to provide you with your requested service. What data we store, we protect within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use or modification.
You are free to refuse our request for your personal information, with the understanding that we may be unable to provide you with some or all of our service.
2. GDPR
i. Your data
You have the option to provide Ellie with various data to help to "train" the AI to write like you. Some of this data is stored on our systems, such as the information that you explicitly provide us from the "Knowledge Base" feature. This data is used to compliment future email replies.
When you ask Ellie to write an email on your behalf, this training data is sent alongside a section of the most recent email replies in the thread to OpenAI, who provide the machine learning models that make Ellie possible. The data is only ever shared with OpenAI for this purpose.
No other data is harvested from your email client.
The result of the reply generation is returned directly to you, and we do not store or share it.
We have requested that OpenAI do not use any data we send them to train future models, so there should be no concern about your information being regurgitated by the AI in future.
We are dedicated to upholding the privacy of your information and agree to never do anything with any data we create from any of your information, except provide you an excellent service.
For financial administration purposes, if you subscribe to a plan then we process your name, email and credit card details. We are not able to process your payment without this information. We will delete this information as soon as you delete your account. If desired, we can send you an invoice. We will then process your company name, address and VAT ID. According to a legal obligation of the Estonian Tax and Customs Administration, we are required to store invoice data for 7 years. After this period we will anonymize this data.
In the unlikely event that you have a complaint about our services, we will process your name, email and the content of and communication regarding this complaint in order to find the best possible solution for you.
We have a commercial interest in using some of your personal data for marketing purposes. We process your email for direct marketing. We process your email when you ask us a question in the chat box or when you indicate that you want to be kept informed about our latest blog articles. We will delete this information as soon as you unsubscribe or indicate that you no longer wish to be contacted by us.
ii. How do we obtain this information?
We have obtained the above information from you as a user of the Ellie extension, because you have provided us with this information. Furthermore, we can obtain your address, as known by the government, through our payment provider Stripe when we validate your VAT number.
iii. What rights do you have with regard to this data?
If you are an EU resident then you have the right at any time to request all the personal information we have for you as dictated by the General Data Protection Regulation (GDPR). Under the same regulation, we will also delete any or all of this information at your request.
In short, these are your full GDPR rights:
-
Access - You can request to view your data at any time.
-
Correct - If you want to have your data adjusted, corrected, supplemented, protected or erased, you can submit a request and we will be happy to make those changes for you.
-
Object - You can object to the processing of your data.
-
Data transfer - If you want to transfer your data to another provider, we will provide your data in a structured and commonly used form that can be accessed by common digital systems.
-
Automated processing - You may always inform us of your view on an automated decision and have this decision reconsidered by a third person.
-
Withdrawal - When we process data based on your explicit consent, you have the right to withdraw your consent. This may have consequences for the services we are able to provide to you.
If you are not an EU resident then we will still afford you these rights if you ask for it, because we believe you should possess them regardless of where in the world you live.
iv. Who receives your data?
We will not provide your data to third parties, unless this is necessary for business operations or is required by law. We try to use as few external services as possible. Your data can be passed on to processors and parties involved in the execution of the agreement. We conclude processing agreements with these third parties to optimally protect your privacy.
Your data will always remain yours. We will never sell your data to third parties.
These are our data-providers and how they use your data;
-
AI Modeling and generating email replies ( OpenAI )
-
Page view analytics ( Simple Analytics )
-
Payment processing ( Stripe )
-
AI Monitoring & Analysis ( Helicone )
-
Knowledge Base data retreival ( Pinecone )
3. External sources
Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and practices of these sites, and cannot accept responsibility or liability for their respective privacy policies.
It's also possible for Ellie to generate URLs that link to external websites. The same applies to these.
4. Transfers of ownership
In the event that we are involved in a merger, acquisition, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will ensure that any new entity to which we transfer your data will continue to honor the terms of this Privacy Policy, or will provide notice and obtain your consent if required by applicable laws.
5. Security
We take the security of your personal information seriously and implement a variety of measures to safeguard it, including:
-
Data Encryption: We use industry-standard encryption protocols to protect data during transmission and storage.
-
Access Controls: Access to personal information is restricted to authorized personnel only, based on the principle of least privilege.
-
Regular Audits: We conduct regular internal security audits and assessments to identify and mitigate potential vulnerabilities.
-
Secure Storage: Personal information is stored on secure servers with robust access controls and monitoring.
-
User Authentication: We employ multi-factor authentication (MFA) to secure our own user accounts and access to our services.
-
Third-Party Security: We ensure that any third-party service providers we use also adhere to stringent security standards and practices.
We are committed to protecting your information and will continue to improve our security practices to keep your data safe.
6. Final provisions
We believe that by following these rules we can keep your data as safe as possible, but if you have any suggestions on how we can improve then let us know!
Your continued use of our website will be regarded as acceptance of our practices around privacy and personal information. If you have any questions about how we handle any of our data, feel free to contact us.
This policy was last updated on the 11th September 2024.
Previous versions:
For accountability we keep the old versions of our privacy policy around to view here.