Legal
Last updated: April 18, 2026
All infrastructure runs on Hetzner servers in the Frankfurt (Germany) data centre. Data never leaves the EEA without appropriate safeguards.
Row-Level Security at the PostgreSQL level guarantees that one workspace's data is completely isolated from others — even in the event of an application bug.
Every significant action in the system is recorded in an audit_log with full context (who, what, when, IP). Log data is retained for 12 months.
Data Controller
Emiri sp. z o.o.
ul. Przykładowa 1
00-001 Warsaw, Poland
hello@emiri.io
Data Protection Officer (DPO)
For GDPR matters, contact the DPO directly:
dpo@emiri.io
Response within 30 calendar days.
Emiri acts in two different roles depending on the category of data:
Controller — User account data
Emiri independently determines the purposes and means of processing registration, billing, and technical data of platform Users.
Processor — Visitor data on the User's website
Conversations through the widget and lead data are processed on behalf of the User (who is the controller toward their own visitors). The legal basis is a Data Processing Agreement (DPA), available on request.
The GDPR grants the following rights. We fulfil all of them upon request sent to dpo@emiri.io:
Right of access
You will receive confirmation of whether we process your data, and a copy of that data.
Right to rectification
We correct inaccurate or complete incomplete data at your request.
Right to erasure
We delete data when the legal basis has ceased or you have withdrawn consent.
Right to restriction
We suspend active processing in contested cases.
Data portability
Data export in JSON or CSV format is available in the panel or on request.
Right to object
You may object to processing based on legitimate interest.
| Data category | Legal basis | Retention period |
|---|---|---|
| Account data (email, password) | Art. 6(1)(b) — performance of contract | Duration of contract + 30 days |
| Billing data | Art. 6(1)(c) — legal obligation | 5 years (tax regulations) |
| Session and security logs | Art. 6(1)(f) — legitimate interest | 12 months |
| Chatbot conversation content | Art. 6(1)(b) — performance of contract (DPA) | 24 months from last activity |
| Newsletter | Art. 6(1)(a) — consent | Until consent is withdrawn |
Some sub-processors are based in the US. Data transfers take place solely on the basis of Standard Contractual Clauses (SCCs) approved by European Commission Decision 2021/914. The list of sub-processors can be found in the Privacy Policy.
Message content sent to the Anthropic and OpenAI APIs is minimised (we send only the current conversation and a knowledge base excerpt) and is not used to train models in accordance with signed DPA agreements.
Emiri uses only technically necessary cookies for session management. We do not use any cookies for advertising or analytics purposes. Details in the Privacy Policy §4.
If you believe that the processing of your data infringes GDPR, you have the right to lodge a complaint with a supervisory authority. You may contact the authority in your country of residence, or the Polish supervisory authority as our lead authority:
Our Data Protection Officer answers all questions about the processing of your personal data.
Contact DPO — dpo@emiri.io