Privacy Policy

Effective from: 11.9.2026
Version: 2.0

This policy explains how ELIA, s.r.o. processes personal data when operating websites, communicating with prospects and customers, and providing the ELIA Asistent service.

The use of cookies, localStorage, sessionStorage, analytics tags, and similar technologies is described in more detail in the separate Cookie Policy and Similar Technologies document.

1. Who Processes Your Data

The controller is:

ELIA, s.r.o.
Hviezdoslavovo námestie 7, 811 02 Bratislava
Company ID: 35 878 185
VAT ID: SK2021791981
Registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No.: 30925/B
Email: contact@elia.sk

If ELIA Asistent processes communications, documents, end-user data, or other customer data as part of the service, ELIA usually acts as a processor on behalf of the customer. Such processing is governed mainly by the contract with the customer and the Data Processing Agreement.

2. Who This Policy Applies To

This policy applies in particular to:

  • visitors to ELIA Asistent websites,
  • prospects interested in the service who contact us or request a demo,
  • customers and persons acting on behalf of customers,
  • users of the administration interface, dashboard, and customer accounts,
  • persons communicating with us by email, form, telephone, or another channel,
  • end users whose data we process where we determine the purposes and means of processing ourselves.

If you communicate with a chatbot or automated assistant deployed on our customer's website, the controller of your personal data is usually that customer. In that case, ELIA processes the data as its processor.

3. What Data We Process

Depending on the specific situation, we may process mainly the following categories of data:

  • identification data, such as name, surname, job title, and company name,
  • contact data, such as email, telephone number, address, and billing details,
  • login and account data, such as user ID, role, tenant, account status, and technical login records,
  • communication data, such as the content of messages, emails, forms, notes, attachments, and support requests,
  • business and contractual data, such as orders, quotations, invoices, payment status, and history of the contractual relationship,
  • technical and operational data, such as IP address, device type, browser, operating system, access time, logs, security events, and session identifiers,
  • analytics data about the use of the website or service, if the relevant tool is enabled and legally permitted,
  • integration configuration data, such as settings of communication channels, webhooks, CRM systems, or calendars,
  • data entered into AI functionality, in particular text inputs, knowledge materials, communication history, and metadata needed to generate a response.

We do not ask you to enter special categories of personal data under Article 9 GDPR, data concerning criminal matters, birth numbers, children's data, or other highly sensitive data into the service unless this is necessary, lawful, and specifically agreed.

4. Purposes, Legal Bases, and Retention Periods

Purpose of processing Typical data Legal basis Retention period
Responding to an inquiry, demo request, or pre-contractual communication name, email, telephone number, company, message content pre-contractual measures, legitimate interest during communication and usually 3 years from the last contact
Concluding and performing a contract with a customer contact persons, orders, service settings, communication performance of a contract during the term of the contract and usually 4 years thereafter for the protection of legal claims
Customer account and dashboard administration user accounts, roles, tenant, login and operational records performance of a contract, legitimate interest in secure operation during the term of the account and for a reasonable period after its cancellation
Providing the AI assistant and related functionality messages, knowledge materials, communication metadata, AI outputs performance of a contract; for customer data, usually processing on behalf of the customer according to the contract, customer settings, and the Data Processing Agreement
Invoicing, accounting, and tax obligations billing data, payments, Company ID, VAT ID, contractual documents legal obligation usually 10 years according to accounting and tax regulations
Security, abuse prevention, and incident handling IP address, logs, security events, tokens, rate limiting legitimate interest, legal obligation usually 12 to 24 months; longer if needed in connection with an incident
Technical support and complaints contact data, problem description, communication, diagnostic data performance of a contract, legitimate interest during handling and usually 3 years after the case is closed
Website analytics cookie identifiers, visit events, technical data consent, where required according to the analytics tool settings or until consent is withdrawn
Service usage analytics and improvement aggregated usage events, technical events, pseudonymized identifiers legitimate interest; consent for some tools according to tool settings and internal retention rules
Marketing communication email, name, company, consent history consent or legitimate interest for existing B2B contacts until unsubscribe or objection; no later than the end of the purpose
Legal agenda and protection of claims contracts, communication, evidentiary materials legitimate interest, legal obligation during limitation periods or the duration of proceedings

If we process data on the basis of consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal.

5. AI Functionality

ELIA Asistent may use artificial intelligence technologies to generate responses, summarize communication, classify requests, suggest next steps, search knowledge materials, and automate communication.

The following applies to AI functionality:

  • inputs and outputs may contain personal data if the customer or end user enters it into the service,
  • AI outputs are probabilistic and may be inaccurate or incomplete,
  • the customer should configure the service so that end users are appropriately informed about the use of automated communication or AI,
  • we do not use customer data to train foundation AI models unless this is specifically agreed or there is a separate legal basis for doing so,
  • the service is not intended for making decisions based solely on automated processing that would have legal effects or similarly significant effects on a data subject.

6. Automated Decision-Making and Profiling

We may automatically sort, label, summarize, or route communication, for example by topic, priority, or case status. Such processing is used to operate the service and improve communication.

We do not make decisions based solely on automated processing, including profiling, that would have legal effects or similarly significant effects on a data subject unless this is expressly stated and legally permissible.

7. Who We May Disclose Data To

We may disclose personal data only to the extent necessary to the following categories of recipients:

  • providers of cloud infrastructure, hosting, databases, authentication, and storage,
  • providers of automation, integration, and communication tools,
  • providers of AI models or AI gateways used to generate responses and process inputs,
  • providers of analytics, security, and monitoring services,
  • providers of payment, accounting, invoicing, and tax services,
  • providers of email, SMS, chat, and other communication services,
  • legal, accounting, tax, and technical advisors,
  • public authorities, where required by law or a legitimate request.

Depending on the current service configuration, providers such as Supabase, n8n, Microsoft Azure, Stripe, PostHog, Google Analytics, Cloudflare, Better Stack, Application Insights, providers of email infrastructure, and providers of communication channels such as Twilio, Meta, Telegram, Microsoft, or Google may be involved. The specific list may vary depending on which integrations the customer has enabled.

8. Transfers Outside the EEA

Some recipients or their technical infrastructure may be located outside the European Economic Area. In such cases, we use appropriate legal mechanisms under the GDPR, in particular an adequacy decision, standard contractual clauses, additional technical and organizational measures, or another valid mechanism.

Where we act as a processor within the service, the rules for international transfers are set out in more detail in the Data Processing Agreement.

9. Data Security

We adopt appropriate technical and organizational measures to protect personal data, in particular:

  • encrypted data transmission using TLS,
  • access management, roles, and the principle of least privilege,
  • separation of customer environments and tenants,
  • user authentication and session management,
  • logging of security-relevant events,
  • protection of public endpoints through rate limiting and security checks,
  • encryption or secure storage of secrets and access credentials where technically available,
  • backups and recovery procedures according to the capabilities of the providers used,
  • internal confidentiality rules and restriction of access to authorized persons only,
  • procedures for handling security incidents.

10. Rights of Data Subjects

Under the GDPR, you have in particular the right:

  • to access personal data,
  • to rectify inaccurate or incomplete data,
  • to erase data,
  • to restrict processing,
  • to object to processing based on legitimate interest,
  • to data portability, if the statutory conditions are met,
  • to withdraw consent, if processing is based on consent,
  • to lodge a complaint with a supervisory authority.

If we process your data as a processor on behalf of our customer, we may ask you to direct your request directly to the relevant customer as the controller. We will provide the customer with reasonable assistance in handling the request.

11. How to Exercise Your Rights

You may exercise your rights by email at contact@elia.sk. When handling a request, we may require reasonable identity verification, especially if without it we cannot safely determine whether the data belongs to the applicant.

The supervisory authority in the Slovak Republic is the Office for Personal Data Protection of the Slovak Republic, website: https://dataprotection.gov.sk.

12. Changes to This Policy

We may update this policy in particular if the service, technologies, legal regulations, or our internal processes change. The current version is available on the ELIA Asistent service website.