Tebelis AI — Privacy Policy
Last updated / Effective date: 7 July 2026
This Privacy Policy explains how Tebelis AI ("Tebelis AI", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with the Tebelis AI platform, websites at tebelis.ai and its subdomains, the mobile application, and the API (together, the "Service"). It should be read together with our Terms of Service and, for business customers, our Data Processing Agreement ("DPA").
1. Our role: controller vs. processor
The Service is used by organisations ("Customers") and their authorised users.
- *We are the processor (or sub-processor)* of the data that a Customer and its users submit
to, or generate within, their workspace — forms, records, projects, attachments, the people they add, and submissions to their public forms ("Customer Data"). We process Customer Data on the Customer's documented instructions and under the DPA. The Customer is the controller and is responsible for the lawful basis and notices for that data, including for any third parties whose personal data it enters into the Service.
- *We are the controller*** of the data we process for our own purposes — for example, account
registration and profile data, authentication and security data, billing data, support communications, and website/usage data described below.
This Policy describes both, and notes which role applies. If you are an individual whose data was entered into a Customer's workspace (for example, you are an employee, contractor, or a public-form respondent of a Customer), the relevant controller is that Customer; please direct your requests to them. We will assist them as their processor (see Section 10).
2. Data we collect
2.1 As controller (our own processing)
- Account & profile — name, email address, password (stored only as a salted, hashed value —
we never store passwords in clear text), profile photo (if you upload one), language preference, and the role/membership assigned to you in a workspace.
- Authentication & security — login and session records, authentication tokens, failed-login
and lockout events, and technical data such as IP address and device/user-agent used to keep accounts secure, detect abuse, and maintain an audit trail of significant actions.
- Billing — for paid plans, your subscription, plan, seat, and payment status. **Payments are
processed by our payment processor (Stripe); we do not receive or store full card numbers.**
- Support & communications — messages you send us and the transactional emails we send you
(for example, email verification, password reset, and workflow notifications).
- Website & usage data — service logs and error/diagnostic logs generated as you use the
Service, and, on mobile, a push-notification token if you enable notifications.
2.2 As processor (Customer Data, on the Customer's behalf)
- Form templates, records, projects, locations, tasks, and configuration created in the
workspace.
- Attachments — files, documents, and photos uploaded to records or chat. **We remove embedded
image metadata (EXIF), including any GPS coordinates, from images on upload.** Location data from a photo is surfaced only where the Customer has explicitly enabled that setting, and then on a read-only basis.
- People data — the individuals a Customer adds to its workspace and any personal data contained
in the records and forms it builds.
- Public-form submissions — data submitted by respondents through a Customer's public intake
forms.
2.3 AI interactions
When you use the AI assistant or other AI features, we process your prompts, the relevant workspace context, and the resulting outputs to provide the feature. Conversations with the assistant are stored so the feature can function and for support; images in stored messages are replaced with a `[photo]` placeholder rather than retained inline. AI usage is metered (token counts and cost) to operate billing and budget controls. See Sections 3 and 8 on AI and retention.
2.4 Cookies
We use a small number of strictly necessary cookies — principally a session cookie to keep you signed in. A few preferences (for example, your language choice) are stored locally on your device rather than in a cookie. We do not use advertising or analytics cookies, and we do not use the Service to build advertising profiles.
3. How we use personal data
We use personal data to:
- provide, operate, secure, and maintain the Service and your account;
- authenticate users, prevent fraud and abuse, and keep an audit trail;
- process payments and manage subscriptions and seats;
- provide AI features you choose to use, and meter their usage for billing and budget controls;
- send service and transactional messages, and respond to support requests;
- comply with legal obligations; and
- maintain and improve the Service, including through aggregated and de-identified data that does
not identify you, any individual, or any Customer.
We do not sell personal data. We do not use Customer Data to train our or any third party's foundation/AI models, except as expressly permitted by the Customer in writing or the DPA.
4. AI providers (managed and bring-your-own)
The AI features are powered either by models we provide (managed AI) or, at the Customer's choice, by the Customer's own connected AI provider (bring-your-own key). Where managed AI is used, prompts and context are sent to our AI model provider(s) (see Section 6) solely to generate the requested output. Where a Customer connects its own provider, that processing is additionally subject to that provider's terms, and we store the connection credentials in encrypted form and use them only to operate the features the Customer enables. AI output may be inaccurate and is not professional advice; it must be reviewed by a human before being relied upon.
5. Legal bases (where the GDPR or equivalent law applies)
We rely on: performance of a contract (to provide the Service and your account); legitimate interests (to secure the Service, prevent abuse, keep audit logs, and improve the Service, balanced against your rights); legal obligation (for example, to keep billing/tax records); and consent where required (for example, certain optional communications or non-essential cookies), which you may withdraw at any time. For Customer Data we process as processor, the Customer determines the legal basis as controller.
6. Sharing and sub-processors
We share personal data only as needed to run the Service:
- Sub-processors that help us operate the Service, including cloud infrastructure/hosting, our
payment processor (Stripe), our transactional email provider, and our AI model provider(s) (including, where used, an EU-region managed model service). A current list of sub-processors and the data-hosting region(s) is maintained on our Sub-processors page.
- Professional advisers and authorities where required by law or to protect our rights, the
Service, or others.
- In a corporate transaction (merger, acquisition, or asset sale), subject to this Policy.
We require sub-processors to protect personal data under terms consistent with this Policy and the DPA.
7. International transfers
We host Customer Data and the personal data we process in the European Union. Our core infrastructure — application servers, database, file storage, and transactional email — runs in an EU region. Some sub-processors are established outside the EEA or process limited data on a global basis (for example, network/traffic metadata for our CDN, or payment data through our payment processor); where personal data is transferred outside the EEA/UK, we use an approved transfer mechanism (the EU Standard Contractual Clauses and, where relevant, the UK Addendum) and, where available, the EU-US Data Privacy Framework, together with appropriate safeguards. The current sub-processors and their hosting regions are listed on our Sub-processors page. Data-residency commitments are as set out in the DPA or the applicable Order.
8. Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it:
- Account & profile data — for the life of your account, and for a limited period afterwards as
needed for legitimate business and legal purposes.
- Customer Data — for as long as the Customer's workspace is active, and otherwise per the
Customer's instructions and the DPA. Records that are deleted go to a recoverable recycle bin and are permanently purged after 14 days; deleting a record also removes its attachments from storage on purge.
- AI assistant conversations — automatically deleted after 90 days of inactivity. A
conversation that continues to be used is retained until it has been idle for that period; an erased user's conversations are removed promptly as part of erasure.
- Audit and security logs — recorded on an append-only basis (they cannot be altered after the
fact) for security, integrity, and compliance, and purged after 180 days (6 months).
- AI-usage records — retained on an append-only basis as needed to operate billing and budget
controls, and as required by tax and accounting law.
- Billing records — retained as required by tax and accounting law.
- Backups — expire on a rolling cycle; data deleted from the live Service is removed from
backups as they age out.
9. Security
We maintain technical and organisational measures designed to protect personal data, including logical isolation between Customer workspaces (enforced at the database with row-level security), encryption of data in transit, encryption at rest of sensitive stored credentials, removal of image (EXIF) metadata on upload, access controls and least-privilege roles, and append-only audit logging of significant actions. No system is perfectly secure, but we work to protect your data and to notify the relevant parties of a personal-data breach as required by law.
10. Your rights
Subject to applicable law (including the GDPR/UK GDPR), you may have the right to access, rectify, erase, restrict or object to processing, port your data, and withdraw consent, and to lodge a complaint with a supervisory authority (our lead authority is the CNIL — France's data-protection authority — as we are established in France).
- For data we control (account, billing, website data), contact us at [email protected].
You can also manage and export much of your data from your account settings.
- For Customer Data (data in a workspace), the Customer is the controller — please direct
your request to that organisation. The Service provides tools that let the Customer export a person's data and erase it. Erasure irreversibly anonymises the person's account — email, password, profile photo, device tokens and sign-in state are destroyed after a grace period, and the account can never be restored.
It does not remove the person's name from the records they created. A completed inspection, incident or check is the Customer organisation's business record, and its integrity depends on who carried it out — an inspection whose author can be erased is worthless as evidence, and the Customer may be legally required to keep it. That retention rests on GDPR Art. 17(3), which limits the erasure right where processing is necessary to establish, exercise or defend legal claims or to comply with a legal obligation. The name therefore remains visible on records, exports, PDFs, the activity feed and the audit trail. The person is removed from people-pickers, assignment lists and seat counts.
Because the Customer — not Tebelis AI — is the controller of those records, a request to remove a name from them is a decision for that organisation, and we act on their instruction.
We will respond within the timeframe required by law and may need to verify your identity.
11. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children below the age required for valid consent in their jurisdiction. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
12. Changes to this Policy
We may update this Policy from time to time. For material changes we will provide reasonable notice (for example, by email or in-product notice). The "Last updated" date above reflects the latest version, and your continued use of the Service after the effective date constitutes acceptance where permitted by law.
13. Contact
Tebelis AI — SASU (share capital €1,000) · RCS Paris 107 153 819 173 rue de Courcelles, 75017 Paris, France Privacy / Data Protection: [email protected] · General: [email protected] EU representative: not required — Tebelis AI is established in the EU (France).