Privacy Policy

    Draft — pending legal review

    This policy explains what personal data we collect, why, and what rights you have under the General Data Protection Regulation (GDPR). It covers this website and the Ezra-AI software.

    Last updated: [TODO: date]

    1. Who is responsible for your data

    • Controller: EZRA-AI SOCIEDAD DE RESPONSABILIDAD LIMITADA
    • Company address: Avda del Conocimiento, 68, 18007 Granada, Spain
    • Madrid office: Calle del Olmo, 8, 28012 Madrid, Comunidad de Madrid, Spain
    • Email: ezra-ai@proton.me
    • Data protection officer: [TODO: confirm whether a DPO is appointed and, if so, add their contact details]

    2. Data this website collects

    • Waitlist form. Your name, company and work email. We use them to contact you about the waitlist and Ezra-AI. Legal basis: your consent when you submit the form (Art. 6(1)(a) GDPR). [TODO: confirm legal basis] You do not have to give us this data, but without it we cannot add you to the waitlist.
    • Emails to us. Your email address and what you write. We use them to reply. Legal basis: our legitimate interest in answering messages (Art. 6(1)(f) GDPR). [TODO: confirm legal basis]
    • Booking a call. [TODO: if you use a booking tool, describe what it collects and who provides it]
    • Technical data. When you visit, our hosting provider processes your IP address and basic request data, such as the page requested and your browser type, to deliver the website and keep it secure. Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).
    • Cookies. Our marketing pages do not set cookies and do not use analytics or advertising trackers. [TODO: confirm, including any analytics enabled in the hosting dashboard]
    • Web chat preview. [TODO: the web chat at /app sends what you type to a third-party AI provider and stores chats in your browser. Remove it from the public site, or describe it here: what data, which provider, legal basis and retention.]

    3. Data the Ezra-AI software handles

    The Ezra-AI software runs on your organisation's own computers. Your files, scan results, logs and notes are stored and processed there by local models.

    Your organisation decides what data to give the software and is responsible for it. For that data, your organisation is the controller. [TODO: confirm roles with legal counsel and in the customer contract]

    What the software sends to Ezra-AI: [TODO: state exactly what, if anything, the software sends to us, such as licence checks, update checks, crash reports or usage statistics. If nothing, say so.]

    4. What may be sent to Anthropic's API

    For the hardest reasoning steps, the software can send a request to Claude, an AI model made by Anthropic, through Anthropic's API. Before anything is sent:

    • a local model removes or abstracts private details;
    • the user is asked to approve the step; and
    • your admin's settings decide what may be sent at all.

    Depending on those settings, a request can contain redacted content, abstracted content or public information. In local-only mode, nothing is sent to Anthropic.

    Anthropic processes these requests under its own terms. [TODO: confirm whose Anthropic API account is used (the customer's or Ezra-AI's), Anthropic's role (processor or sub-processor), and how long Anthropic keeps API data under the terms that apply]

    5. Who receives your data

    We do not sell your data. We share website data only with service providers that help us run the website and store waitlist sign-ups: our hosting provider and our database provider. They may only use it to provide their service to us. [TODO: decide whether to name these providers after legal review]

    6. Transfers outside the European Economic Area

    Some of our providers, including Anthropic, may process data outside the European Economic Area. [TODO: list the safeguard used for each provider, for example an adequacy decision or Standard Contractual Clauses]

    7. How long we keep data

    • Waitlist sign-ups: [TODO: retention period], or until you ask us to delete them.
    • Emails to us: [TODO: retention period].
    • Hosting logs: [TODO: retention period set by the hosting provider].

    8. Your rights

    Under the GDPR, you can ask us to:

    • give you a copy of your data (access);
    • correct it (rectification);
    • delete it (erasure);
    • limit how we use it (restriction);
    • stop using it, where we rely on legitimate interest (objection);
    • send it to you or another company in a common format (portability).

    Where we rely on your consent, you can withdraw it at any time. This does not affect what we did before you withdrew it.

    To use these rights, email ezra-ai@proton.me. We may ask you to confirm your identity.

    You can also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (www.aepd.es).

    9. Changes to this policy

    If we change this policy, we will update this page and the date at the top.