Privacy Policy
Last updated: July 5, 2026
This Privacy Policy describes how EquilAI ("EquilAI", "we", "us", or "our"), a company registered in Finland under business ID (Y-tunnus) 3546344-3, with its registered office at Saturnuksenkuja 2 B 45, 01480 Vantaa, Finland, collects, uses, discloses, stores and otherwise processes personal data about users of the EquilAI platform and services (the "Service") and through our website (the "Website").
Depending on the context, references to "you" or "your" refer to a Customer, User, Visitor and/or End-User as defined below.
In this Privacy Statement:
"Channel Integration" means a connection between a Customer Bot and a third-party messaging, email, or commerce platform (such as Telegram, Discord, Gmail, Microsoft Outlook, or Shopify) that enables the Customer Bot to receive and respond to messages, or to retrieve information, on that platform.
"Conversation Data" means content inputted by an End-User into a Customer Bot in a production environment, including any files the End-User attaches to a chat message, and data generated by the Customer Bot in a conversation with an End-User, including messages exchanged through Channel Integrations.
"Customer" means any person or business who purchased a subscription to the Service or is using the free version of the Service.
"Customer Bot" means a program designed to automate interactions with End-Users of a service or website, including any configuration data or other supporting data that is developed using EquilAI software compatible with the Service by Customers, or third parties on behalf of a Customer or by EquilAI for the benefit of the Customer and that is hosted through the Service.
"End-User" means an individual interacting with a Customer Bot served through our Services, whether via the embeddable widget, API, or a Channel Integration.
"Personal data" refers to any information that identifies or could be reasonably associated with an individual.
"Visitor" means an individual browsing our Website.
"Usage Data" means data about the Users' use of the Service, which may contain personal data where identifying information is necessary but excluding any Conversation Data. Usage Data may include personal data about the employees and contractors of the Customer but not about End-Users interacting with Customer Bots.
"User" means an individual using the Service on behalf of the Customer, such as an employee of the Customer.
The contact details of the person responsible for data protection is the following: [email protected]
1. What Personal Data is Collected Through The Service
End-Users
We collect analytics data, which includes:
- The operating system and language of a device
- The IP address from which a device accesses the Service
- The country, state, city and postal code where the device is located
- Navigation data, such as pages viewed, number of connections to the Service, duration of a session, and date of connections to the Service
- The page on which the conversation took place and the referring website or application from which the End-User arrived, which we use in aggregate to give the Customer traffic-source insights (for example, whether visitors arrived from search, social, or a referring site). This is not used to identify an individual End-User.
- Conversation feedback ratings voluntarily submitted by an End-User (thumbs up/down)
We collect this data when an End-User interacts with a Customer Bot for the sole purpose of providing the Service to our Customers. This data is not personally linked to a specific End-User and is transmitted to us in aggregate form.
We process personal data about End-Users on behalf of our Customers pursuant to their instructions.
To generate Customer Bot responses, Conversation Data (the messages exchanged with the Customer Bot, together with the relevant Customer Bot configuration and knowledge base content) is transmitted to our AI provider, OpenAI, which processes it solely to return a response and does not use API-submitted data to train or improve its models. We have contractually restricted OpenAI from logging or retaining request content beyond what is strictly necessary to fulfil that purpose. Where the Customer has enabled PII redaction, personally identifiable information is automatically detected and removed from Conversation Data before it is stored on our systems or transmitted to OpenAI.
The PII redaction feature covers email addresses, international telephone numbers, payment card numbers (validated with the Luhn checksum), and national identification numbers (such as Finnish and Swedish personal identity codes, US social security numbers, and equivalent government-issued identifiers). Where PII redaction is enabled, for End-Users interacting via the embeddable website widget, redaction is performed locally on the user’s device before any data is transmitted to our servers, so that such information never reaches EquilAI’s infrastructure. For End-Users interacting via the public API or Channel Integrations, redaction is applied on our servers before the message is stored, logged, or forwarded to our AI provider. The original values are not retained in either case.
Should EquilAI become aware that any Conversation Data stored on our systems contains unredacted personal identification details (such as government-issued identification numbers), we will delete the relevant conversation records from our systems promptly upon discovery.
End-Users may attach image files and PDF documents (up to 10 MB per file) to messages sent through the embeddable widget. Attached files are stored on our servers within the European Union / European Economic Area and are automatically and permanently deleted seven (7) days after upload. To generate a response, attached images may be transmitted to our AI provider, OpenAI, where the Customer Bot’s underlying model supports image input, and the text extracted from attached PDF documents is transmitted in the same manner as other Conversation Data. After the seven-day deletion, conversation transcripts retain only the file name, type and size of an attachment, not its content. Automated PII redaction applies to message text but not to the contents of attached files, so End-Users should avoid attaching files that contain sensitive personal data.
Where a Customer has enabled a Channel Integration (such as Telegram, Discord, Gmail, Outlook, or Shopify), Conversation Data from those channels is received by EquilAI via the relevant third-party platform API and processed in the same manner as described above. The third-party platform independently collects and processes data about its own users in accordance with its own privacy policy.
Where a Customer has enabled live chat / human handoff, an End-User conversation may be escalated to one of the Customer’s own human agents, who can then view that conversation and reply. In this case the Customer’s agents process the Conversation Data under the Customer’s own responsibility as data controller. EquilAI facilitates the connection and stores the conversation as part of providing the Service.
We do not use Conversation Data or other End-User personal data for any other purpose, which includes analytics, algorithms, model improvements or training.
Users and Customers
We collect the following personal data:
- Full name, email and password (passwords are stored only in hashed form)
- Where you choose to sign in with Google, the Google account identifier, name and email address provided to us by Google
- Billing and subscription data processed through our payment provider, Stripe. We store a Stripe customer and subscription identifier; full payment card details are collected and stored by Stripe and are not stored on our servers
- Two-factor authentication (2FA) data: where you enable TOTP-based two-factor authentication, we store an encrypted TOTP secret associated with your account. This secret is used solely to verify your identity at login and is never transmitted to third parties.
- Channel Integration credentials: where you connect a Channel Integration, we store the necessary authentication tokens or credentials (for example, a Telegram bot token, a Discord bot token, or a Microsoft OAuth refresh token) required to send and receive messages on your behalf. These are stored securely and used exclusively to operate the relevant integration.
- Content of communications transmitted to us by Users, which could contain personal data, including support ticket submissions
- Content updated to the Customer Bot, which could contain personal data, including:
- Text responses and system prompts
- Images and branding assets (logo, icon)
- Knowledge base documents (uploaded files such as PDF, DOCX, TXT, CSV, JSON)
- Knowledge base content retrieved via the website scraping feature
- Bot configuration settings (allowed domains, creativity settings, integration settings)
- Analytics data which may include:
- The operating system and language of a device
- The IP address from which a device accesses the Service
- The country, state, city and postal code where the device is located
- Navigation data, such as pages viewed, number of connections to the Service, duration of a session, and date of connections to the Service
We use the content updated to the Customer Bot for the sole purpose of providing the Service to our Customers.
We do not use this content for any other purpose, including to perform analytics and model improvements, create algorithms or for training purposes.
2. What Personal Data is Collected Through The Website
Visitors
When a Visitor fills out a form on our Website, we collect the following personal data:
- Full name
- Phone number
- Email address
- Employment information (title, employer)
- Any other information that Visitors voluntarily communicate to us
If, and only if, a Visitor consents to analytics cookies through our cookie banner, we use Microsoft Clarity, a product analytics tool provided by Microsoft, to understand how our Website is used. Where this tool is active, we automatically collect:
- The device type, operating system, browser and language
- The IP address from which a device accesses the Website (used to derive approximate location and then masked by Microsoft Clarity)
- The approximate location (such as country and region) derived from the IP address
- Navigation and interaction data, such as pages viewed, referring page, clicks, scrolls, session duration and dates of connection
Microsoft Clarity may record anonymised session interactions (such as mouse movement, scrolling and clicks) to produce heatmaps and aggregate usage insights. We never send Microsoft Clarity your name, email address or any other directly identifying detail. For signed-in users only, we attach an irreversible one-way hash of your internal account identifier so we can understand a single user's experience across their own devices and browsers; this hashed value cannot be reversed back into your identity. Microsoft acts as our sub-processor for this purpose and processes the data in accordance with its own privacy terms.
You may opt out of this collection at any time by declining analytics cookies through our cookie banner, or by adjusting your stored cookie preference to “Necessary only”.
3. Why We Process Personal Data
We process the personal data collected through the use of the Service or the Website for the following purposes:
Operation of the Service, Customer Service and Technical Support
We process the personal data collected through the Service to provide services to our Customers, including customer service and technical support, in accordance with their instructions. Conversation Data is processed only for this purpose.
As part of the Service, we will process the personal data of Users and Visitors to respond to their requests, including requests for assistance, account processing, and support ticket management.
Communication with Users, Customers and Visitors
We process personal data about Users and Customers to communicate with them about their use of the Service or the Website. We may also send marketing communications about us, our products and promotions, but only to Customers and Users that agreed to receive marketing communications from us. We comply with all applicable regulations regarding unsolicited commercial messages. If you no longer wish to receive marketing communications from us, you may unsubscribe at any time by writing to us at [email protected]
If a Visitor has provided personal data, we use it for communication purposes.
Identification and Authentication of Users and Customers
To render the Service, we process personal data to identify and authenticate Users and Customers, including via password verification, Google OAuth, and TOTP-based two-factor authentication where enabled.
Product Improvement
We process aggregated Usage Data to improve our products and services, identify trends in product use and develop new products and offerings.
We also use browser cookies and other tracking technologies to improve our Website.
Personalization of our Service and Website
We process the data collected through the Website to offer Visitors content that corresponds to their situation or interests. For example, the home page of the Website may be displayed according to language preferences, and the products and services displayed may be different depending on geographic location.
We may also use personal data to customize our Customers' and Users' experience of the Service.
Maintenance and Security
We process the data collected through the Website and the Service and data from analytics tools to monitor Users' and Customers' use of the Website and the Service, to prevent misuse of the Website or the Service, to identify problems or bugs with the Website or the Service, and to determine what features need to be improved.
We may use data collected automatically to ensure the security of the Website, the Service and our computer systems (e.g. to prevent hacking or to deter, monitor and prevent fraud).
Marketing
We do not currently engage in behavioral advertising, retargeting, or the building of advertising audiences, and we do not sell personal data. We do not use third-party advertising cookies on our Website.
Where you have provided your details (for example, through our contact form) or otherwise consented, we may send you marketing communications about our products and services. You can opt out at any time as described in the “Communication” section above.
Data collected through the Service, including Conversation Data, is never used for marketing purposes.
Comply with legal obligations
Where applicable, we process personal data to comply with laws and regulations that apply to our activities, including for dispute resolution, responding to legal requests and cooperating with regulatory entities or courts.
4. How We Process and Transfer Personal Data
We retain your personal data only as long as it is necessary for our intended processing purposes or, as the case may be, until you or our Customer requests that we delete it. The retention period is determined by the purpose for which the data was collected and by any applicable legal or regulatory requirements.
Conversation Data (including End-User messages, Customer Bot responses, and feedback ratings) is automatically and permanently deleted from our systems after a maximum of twelve (12) months from the date of collection. Files attached to chat messages by End-Users (images and PDF documents) are subject to a shorter retention period and are automatically and permanently deleted seven (7) days after upload; only the file name, type and size are retained as part of the conversation transcript. Where an account is deleted, we anonymise the user record rather than permanently erase it, in order to preserve the integrity of associated billing records as required for accounting and tax compliance purposes.
EquilAI operates primarily within the European Union. Some data relating to the use of the Service and the Website, system automation, support services and billing are processed by our service providers through facilities that may be located in other jurisdictions. Therefore, your personal data may be accessed by jurisdictions outside your country of residence.
Personal data about End-Users collected through the Service (such as Conversation Data) is stored electronically on servers located within the European Union / European Economic Area, where our primary hosting infrastructure is based. Data stored within the EEA benefits from the protections afforded by EU data protection law.
Where Channel Integrations are enabled, Conversation Data passes through the infrastructure of the relevant third-party platform (Telegram, Discord, Google, Microsoft, or Shopify) before reaching EquilAI. These platforms process data in accordance with their own privacy policies and may store message content independently of EquilAI.
We ensure that the transfer of your Personal Data is made in a secure manner, with appropriate safeguards concerning the nature of the personal data being transferred.
Certain of our sub-processors, including OpenAI, Stripe, Google, Microsoft and Resend, are established in or process data in the United States. In case of transfers of personal data outside the European Economic Area, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses approved by the European Commission and other safeguards in compliance with the GDPR.
Analytics data generated through Microsoft Clarity is stored on servers controlled by Microsoft.
5. How We Protect Personal Data
EquilAI has put in place organizational, physical and technical measures to secure the personal data entrusted to us. These measures include: password hashing; field-level encryption for sensitive stored credentials such as two-factor authentication secrets and channel integration tokens; encryption of data at rest on our hosting infrastructure; secure transmission of all data via HTTPS/TLS; and access controls limiting data access to authorized personnel. You can ask for a complete description of the security measures in effect to protect personal data at any time by writing to us at [email protected]
Your personal data is hosted on servers operated by our service providers and is protected against unauthorized access or use by security measures proportionate to the sensitivity of the data. Any financial data is subject to additional security measures that comply with the standards established by payment card networks.
Our employees and suppliers are informed of the confidential nature of personal data collected through the Website and the Service. They are also aware of the appropriate security measures to prevent unauthorized access to personal data through an enterprise-wide cybersecurity policy and training.
6. How We Share Personal Data
We only share personal data in the manner described in this statement. Your personal data may be disclosed to the categories of recipients below for the following purposes:
EquilAI Employees
Personal data is accessible to our officers and employees, who must have access to it as part of their duties. Each employee is bound by a confidentiality agreement.
Customers
We share personal data collected through the Service about End-Users with the Customer controlling the Customer Bot with which the End-User interacts. The Customer is the controller with respect to such personal data.
Service Providers and Sub-Processors
We share personal data with service providers (acting as our sub-processors) that enable us to deliver our services more efficiently. We only share personal data with service providers that agree to keep personal data confidential and which implement security and personal data protection measures comparable to our own. The sub-processors we currently rely on are:
- OpenAI: generation of Customer Bot responses from Conversation Data, Customer Bot configuration and knowledge base content (United States, via API). OpenAI processes this data solely to generate responses and does not use API-submitted data to train or improve its models. Where PII redaction is enabled by the Customer, personal data is removed from Conversation Data prior to transmission to OpenAI.
- Stripe: payment processing and subscription billing (handles payment card data; we store only customer and subscription identifiers).
- Google: (i) optional “Sign in with Google” authentication; (ii) the Gmail API for the Gmail Channel Integration, only where the Customer has enabled and authorized this integration. In the case of the Gmail integration, email content constitutes Conversation Data and is processed as described in Section 1.
- Microsoft: (i) Microsoft Clarity for Website product analytics, only where the Visitor has consented to analytics cookies; (ii) Microsoft Graph API for the Outlook Channel Integration, only where the Customer has enabled and authorized this integration. In the case of the Outlook integration, email content constitutes Conversation Data and is processed as described in Section 1.
- Telegram: Telegram Bot API for the Telegram Channel Integration, only where the Customer has enabled this integration. Conversation Data exchanged via Telegram passes through Telegram's infrastructure. Telegram processes data in accordance with its own privacy policy (United Arab Emirates / worldwide).
- Discord: Discord API for the Discord Channel Integration, only where the Customer has enabled this integration. Conversation Data exchanged via Discord passes through Discord's infrastructure. Discord processes data in accordance with its own privacy policy (United States).
- Shopify: Shopify API for the Shopify integration, only where the Customer has connected their store. Used to retrieve product and order information so the Customer Bot can answer related End-User questions. Where an End-User provides an order number or email to look up an order, that identifier is sent to Shopify to retrieve the result.
- Resend: delivery of transactional and notification emails (such as contact-form notifications, password-reset messages, and internal new-signup notifications to our team).
- Our cloud hosting and database providers: hosting of the Website, the Service and the database in which account data, Customer Bot content and Conversation Data are stored. Our primary server infrastructure is located within the European Union / European Economic Area.
An up-to-date list of our sub-processors is available on request by writing to [email protected].
Affiliates
We may share your personal data with our business family for the purposes outlined in this statement.
Other Third Parties
If required by law: We may also disclose personal data to third parties as otherwise permitted or required to do so by law or if we are compelled to do so by a competent authority. We may disclose personal data in connection with legal proceedings if necessary to protect our rights or those of others or to meet national security or law enforcement requirements.
Transfer of business: If the sale or restructuring of all or part of our business is contemplated, we may disclose personal data to the persons or organizations involved before and during the transaction, whether or not the transaction ultimately takes place. In such a case, these persons or organizations commit to us to maintain the confidentiality of personal data so disclosed and to use the same exclusively to evaluate the contemplated transaction and in accordance with this statement if the transaction is completed.
7. What Are Your Rights Over Personal Data
We may verify the identity of individuals asking to exercise their rights with respect to their personal data. Any information collected to perform such verification will not be used for any other purpose.
Data Controlled by Customers
When we process your personal data on behalf of our Customers (e.g. if you are an End-User and you interact with a Customer Bot), you must directly contact our Customer to exercise your rights in connection with your personal data. When this scenario applies, we will forward your requests to the relevant Customer and will cooperate with the Customer to respond to your request. We are not authorized by our Customers to provide information to End-Users. Conversation Data and personal data about users are typically processed on behalf of our Customers.
Right to Deletion (Account Deletion)
Customers and Users may request deletion of their account at any time through the account settings page in the Service dashboard, or by writing to us at [email protected]. Deletion requests are reviewed and processed within the timeframe required by applicable law (no later than one calendar month under GDPR). Upon processing, all personal data associated with the account is permanently anonymised and Customer Bot data is deleted, except where retention is required for accounting and legal compliance purposes.
Withdrawal of Consent
Your browser allows you to withdraw your consent to certain processing of your personal data, in particular by preventing the placement of browser cookies.
If you wish to withdraw your consent to the processing of your personal data beyond what is permitted by the browser, please contact us by writing to us at [email protected]. Using the Website or the Service entails some processing of your personal data. The only way to stop the processing of your personal data is to stop using the Website and the Service.
Right of Access, Rectification and Portability
Subject to what is stated in the 'Data controlled by Customers' section, if you would like to access personal data we have about you or have inaccurate personal data corrected in our files, you may make a request at [email protected]. We will respond to your request promptly and no later than required under applicable law. If required by law, we will provide personal data in a structured, commonly used and machine-readable format.
Restriction of Processing
Subject to what is stated in the 'Data controlled by Customers' section, End-Users may request the restriction of the processing of their personal data where such processing is unlawful, if End-Users contest the accuracy of such personal data or where deletion of personal data is not permitted under applicable law. You may make a request at [email protected].
Right to Limit the Use and Disclosure of Personal Data and/or Opt-In for Sensitive Information Collection
Subject to what is stated in the 'Data controlled by Customers', you may have the right to limit the use and disclosure of your personal data. Although EquilAI currently does not share personal data with third parties for purposes other than those described in this statement, we remain committed to ensuring you can exercise this right should that practice change in the future. Specifically, you will have the option to opt-out before your personal data is disclosed to a third party or used for a purpose materially different from the purpose(s) for which it was originally collected or subsequently authorized by you.
Moreover, for sensitive personal data processing, EquilAI will always require your affirmative express consent (opt-in) before such information is disclosed to a third party or used for a purpose other than those originally stated or subsequently authorized by you.
You can make a request at [email protected].
Complaint
If you wish to lodge a complaint in relation to the processing of your personal data by EquilAI, you may do so by writing to [email protected]. You may also lodge a complaint about our processing of personal data to the supervisory authority of your place of residence, which for Finnish residents is the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu).
8. How we use cookies and other tracking technologies
We use the following categories of cookies and similar technologies:
- Strictly necessary: required for the Website and the Service to function (for example, to keep you signed in and to remember your cookie choice). These are always active and do not require consent.
- Analytics: set by Microsoft Clarity to help us understand how the Website is used. These are used only with your consent.
We do not use advertising or third-party tracking cookies. Analytics cookies are not placed unless you select “Allow all” in our cookie banner; if you select “Necessary only”, no analytics cookies are set. You can also control the storage of cookies through your browser settings.
If you want to understand how we use Microsoft Clarity, refer to the ‘What Personal Data is Collected through the Website’ section.
9. Minors
EquilAI Service and Website do not knowingly collect personal data from children under the age of 16, as the Service and Website do not target children. Children under 16 years of age should not use our Service or Website or provide EquilAI with any personal data without the consent of a parent or legal guardian. Should we become aware of the collection of personal data from a child under 16 years of age, we may promptly remove this information without prior notice. If you discover such an incident, please contact [email protected]
10. Information for individuals in the EEA, the UK and Switzerland
As a Finnish company, EquilAI complies with the EU General Data Protection Regulation (GDPR). We only process personal data based on the following legal basis:
- With your consent, where applicable
- To fulfill our obligations under our agreements with Customers and Users
- Where it is necessary, based on our legitimate interests, to:
- render the Service
- manage our relationship with you
- operate our Website
- provide support to Customers, Users, End-Users and Visitors
- improve our services based on aggregated data
- detect, prevent, or investigate misuse, fraud, security incidents or other illegal activities about the Service or use of the Website
- To comply with our legal or regulatory obligations
Your personal data might undergo processing, transfer, or disclosure in other countries where our affiliates and service providers operate or have servers. We ensure that the recipient of your personal data maintains an adequate level of protection. This is achieved through arrangements such as Standard Contractual Clauses or other approved transfer mechanisms, as determined by the European Commission or the relevant data protection authority.
If you are a Customer, we strongly advise entering into a Data Processing Agreement (DPA) with us. This document constitutes a formal agreement that acknowledges EquilAI's GDPR compliance and assists you in upholding GDPR standards in your utilization of EquilAI as a data processor. A signed copy of our DPA can be obtained by contacting [email protected]
EquilAI is committed to implementing appropriate technical and organizational measures to ensure the security and confidentiality of your personal data. This includes protecting data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
EquilAI has appointed a Data Protection Officer (DPO) who is responsible for ensuring compliance with data protection laws and regulations, including GDPR. You can reach out to our DPO by email at [email protected]
For any additional information with respect to our processing of personal data, you may contact us at [email protected].
11. Modifications
We may modify this Privacy Statement from time to time to reflect changes in our personal data processing practices or any requirement under applicable law. If a modification is made, the new statement will be available through the Service and on this Website.
The statement posted via this website shall be deemed to be the statement then in effect and the date at the top of the statement will be updated to reflect the date of effectiveness. We recommend that you check this website from time to time to remain informed of any changes in this statement.