Who we are
This privacy policy applies to website.eldris.ai and is operated by EldrisAi OÜ, an Estonian company registered under number 17298529 with its registered office at Ruunaoja tn 3, Tallinn, 11415, Estonia. We are the data controller for any personal information you submit through this site or any of its forms. The named contact for any privacy question is the founder, reachable by email at compliance@eldris.ai, by phone on 020 3996 2101, or through the Talk to Eldris chat on every page. We are an EU-established company (Estonia), and we treat the GDPR as the floor of our practice rather than the ceiling.
What we collect
We collect only what we need to quote, deliver and support your website translation engagement. From the contact form we take your name, work email, current website URL, target markets, rough product count and your free-text message. We do not store IP addresses against form submissions and we do not run third-party advertising trackers. We use Google Analytics to count visits and see how the site is used. Our network-edge layer is Cloudflare, which inspects request metadata briefly for security and abuse-prevention purposes and does not retain it for marketing.
How we use it
We use your information to respond to quote requests, deliver the migration and translation work you have engaged us for, send operational updates while your site is being built, and bill you accurately during your monthly engagement. We do not send marketing emails to anyone who has not explicitly opted in. The named processors we share data with are Cloudflare (edge security and DNS), Supabase (our database, hosted in EU regions), Resend (transactional email delivery), Google (Google Analytics, which counts visits), LiveKit (voice conversations in the Talk to Eldris drawer) and OpenAI (drafting replies to messages typed into the Talk to Eldris chat). Cloudflare, Supabase and Resend sit under written processor agreements with EU-standard data protection terms. We do not sell your data and we do not pass it to any other party.
Cookies
This site uses a minimal cookie banner that loads on first visit. Functional cookies needed to make the site work — session, language, security — are set without consent because they are strictly necessary under GDPR Article 6. The site also loads Google Analytics, which sets its own cookies (such as _ga) to count visits and see how pages are used. We do not run any third-party advertising trackers: no Meta Pixel, no TikTok pixel, no LinkedIn Insight Tag.
Your rights (GDPR)
You have the full set of GDPR rights over any data we hold on you. The right of access — ask us what we hold and we will send it. The right of rectification — tell us what is wrong and we will correct it. The right of erasure — ask us to delete your record and we will, subject only to bookkeeping retention obligations. The right to restrict processing, the right to data portability, and the right to object to any specific processing activity. To exercise any of these rights, email compliance@eldris.ai or use Talk to Eldris on any page, marking it as a GDPR request and naming the right you are exercising. We respond inside 30 calendar days. We do not charge a fee for any standard request.
Retention
Quote requests where we did not win the business are deleted automatically 12 months after submission. Active client records are retained for the full duration of your engagement plus seven years afterwards, because UK and Estonian bookkeeping law requires invoice and contract records to be kept for that period for tax and audit purposes. Backups roll on a 90-day window, which means a deletion request takes up to 90 days to fully clear from backup snapshots. After seven years, archived client records are purged in their entirety. None of this data ever leaves our processor stack.
Data transfers
Our database (Supabase) runs in the EU-Frankfurt region. Cloudflare edge security operates globally but does not retain personal data at non-EU edges. Transactional email delivery (Resend) processes inside EU and US regions, covered by EU Standard Contractual Clauses for the US leg. Google Analytics, LiveKit and OpenAI may process data outside the EU. We are an Estonian-registered operator, not a US or UK entity, which means your data falls under direct EU jurisdiction without an adequacy bridge. We do not transfer personal data to any country outside the EU/UK without an SCC in place and a documented lawful basis.
Updates to this policy
We update this policy when our processing genuinely changes — a new processor, a new data category, a new retention window — and we update the last-updated date at the top of this page every time. Material changes that affect active clients are notified by email at least 14 days before they take effect, so you can object or close your account if you disagree. We do not use vague catch-all clauses about updates from time to time. Every revision has a date, a reason, and a record. Old versions are available on request by email to compliance@eldris.ai.
Contact for privacy concerns
Privacy questions go directly to the founder by email to compliance@eldris.ai, or through Talk to Eldris on any page, marked as a privacy question. The founder personally reviews these requests and responds inside 30 calendar days, sooner in most cases. If you are unhappy with the resolution, you have the right to escalate to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) as our supervisory authority, or to your own national data protection authority if you are an EU resident outside Estonia. We would always rather resolve a concern directly first.