Privacy policy

Last updated 13 September 2026

This policy covers the Gemerald website and the Gemerald platform. It is written to be read, not to be survived — if anything here is unclear, ask us and we will answer plainly.

Two different relationships

Gemerald sits in two positions, and your rights differ between them.

  • When you visit this website or open an account, we decide what to collect and why. In data-protection terms we are the controller, and this policy is the full answer.
  • When you run an agent and your customers talk to it, the personal data in those conversations is yours. You decide what is collected and why; we process it on your instructions. That relationship is governed by the data processing addendum, not by this policy.

What we collect

From visitors to this website:

  • What you type into a form — name, company, email, phone and your message.
  • Standard request data your browser sends, including IP address and user agent, used for security and abuse prevention.
  • With your consent, analytics about which pages were viewed and which links were followed.

From account holders, in addition:

  • Account and billing details, including the plan you are on and the record of what was charged.
  • The content you give the agent to work from — your site, catalog, price list and documents.
  • Operational logs of how the platform was used, which is what lets us debug a problem you report.

Why we use it

  • To provide the service you asked for, and to keep it working.
  • To answer an enquiry you sent us.
  • To bill you, and to keep the accounting records the law requires us to keep.
  • To protect the service against abuse, fraud and attack.
  • With your consent, to send you product updates — which you can stop at any time, in one click, and we will honour it the first time.

We do not sell personal data, and we do not share it with third parties for their own marketing.

How AI models are used

The agent is built on large language models operated by third-party providers. Conversation content is sent to those providers so they can generate the reply, under contracts that prohibit them from using it to train their models.

A model can be wrong. The platform gives you the transcripts, guardrails, and a handover to a human precisely because "the AI said it" is not a defence you should ever have to rely on.

Who else is involved

We use service providers to run the platform. Each is bound by contract to process data only on our instructions, and only to the extent their function requires:

  • Cloud hosting and storage.
  • AI model providers, as described above.
  • Messaging platforms, where you have connected a channel — for example WhatsApp, Instagram or Messenger. Traffic on those channels is also subject to that platform’s own terms.
  • Payment processing, where you are on a paid plan. We do not store full card numbers.
  • Email delivery, analytics and error monitoring.

The current list of providers is available on request, and account holders are notified before a new one is added.

Where data is processed

Gemerald operates internationally, so personal data may be processed outside the country you are in, including outside the European Economic Area.

Where that happens, transfers are made under a recognised legal basis — an adequacy decision, or Standard Contractual Clauses with additional safeguards. The specific arrangement for your account is set out in the data processing addendum, and we will tell you what it is if you ask.

How long we keep it

  • Enquiries from this website: kept while we are dealing with them and for a reasonable period after, then deleted.
  • Account data: kept for as long as the account is open.
  • Conversation data: kept for as long as you keep it. You control retention, and deleting it in the platform deletes it.
  • Billing records: kept as long as the applicable accounting and tax law requires, which is longer than we would otherwise keep anything.
  • Backups: deleted content persists in backups for a limited window before those roll over.

Your rights

Depending on where you live, you have some or all of the following rights over personal data we hold about you as a controller: access, correction, deletion, restriction, portability, objection, and withdrawal of a consent you previously gave.

Write to us and we will act on it. We will not charge you for it, and we will not make you explain why. If you are unhappy with how we handled it, you can complain to your local data protection authority.

If your data reached us because you talked to a business’s Gemerald agent, that business is the controller — send the request to them, and we will support them in answering it.

Security

Data is encrypted in transit and at rest. Access to production systems is restricted to the people who need it, authenticated individually, and logged. Changes are reviewed before they ship.

No one can promise that a breach is impossible. What we will do is tell you — promptly, and with what we actually know rather than a holding statement.

Cookies

Essential cookies keep the site and your session working, and cannot be turned off without breaking it. Analytics and marketing cookies are off until you accept them, and the banner’s "Essential only" really is essential only.

You can change your choice at any time from "Cookie settings" in the footer.

Children

The platform is for businesses. It is not directed at children, and we do not knowingly collect their data. If you believe we have, tell us and we will delete it.

Changes to this policy

If we change it materially we will say so here and, for account holders, by email before it takes effect. The date at the top is the date of the current version.

Questions about this document? Email team@gemerald.ai and a person will answer.