Privacy Policy
How we handle your data · Effective July 12, 2026
1.Overview
This Privacy Policy explains how ERAG (“ERAG”, “we”, “us”) collects, uses, and protects personal data when you use the ERAG platform, websites, and services (the “Service”). We designed ERAG around data minimization and access control, and this policy reflects that.
The short version: we collect what we need to run the Service, we do not sell your data, and we do not use the documents you upload to train foundation models.
2.Who is the data controller
For account and marketing data, ERAG is the controller. For the documents and content you upload and process through the Service (“Customer Data”), you are the controllerand ERAG is your processor, acting on your instructions under our agreement and, where applicable, a Data Processing Addendum.
3.Data we collect
- Account data — name, work email, organization, and authentication details when you register.
- Billing data — plan, usage counts, and payment metadata. Card details are handled by our payment processor; we do not store full card numbers.
- Customer Data — the documents, files, and connected content you ingest, plus the queries you run and the answers returned.
- Usage and device data — logs, IP address, browser/device type, and product interactions, used for security, debugging, and improving the Service.
- Communications — messages you send us (support, sales) and, if you opt in, marketing preferences.
4.How we use data
- to provide, secure, and operate the Service, including indexing and answering over your Customer Data;
- to authenticate users and enforce access controls and tenant isolation;
- to process payments and administer plans, including usage-based billing;
- to provide support and communicate about the Service;
- to monitor, prevent, and investigate abuse, fraud, and security incidents;
- to comply with legal obligations; and
- with your consent, to send product and marketing updates (you can opt out at any time).
We do not use your Customer Data to train foundation models, and we do not sell personal data.
5.Legal bases (where GDPR/UK GDPR applies)
- Contract — to deliver the Service you signed up for.
- Legitimate interests — to secure, maintain, and improve the Service, balanced against your rights.
- Consent — for optional marketing and non-essential cookies.
- Legal obligation — to meet accounting, tax, and compliance duties.
6.Sub-processors and sharing
We share data with vetted service providers who help us run the Service — for example, cloud hosting, AI model providers you configure, email delivery, analytics, and payment processing. They may process personal data only on our instructions and under appropriate safeguards. We may also disclose data to comply with law or protect rights and safety. We do not sell your data. A current list of sub-processors is available on request at privacy@erag.one.
7.International transfers
We may process data in countries other than yours. Where we transfer personal data across borders, we use appropriate safeguards such as Standard Contractual Clauses or an equivalent lawful transfer mechanism.
8.Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest for stored documents, access controls enforced inside the search index (not merely post-filtered), tenant isolation, audit logging, and least-privilege access. No system is perfectly secure, but security is a first-class design goal of the Service.
9.Data retention
We keep account and billing data for as long as your account is active and as needed to meet legal and accounting obligations. Customer Data is retained while your account is active; on termination we make it available for export for 30 days and then delete it in the ordinary course, subject to backups that age out on a rolling basis. You can delete documents from the Service at any time.
10.Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise these rights, contact privacy@erag.one. If your personal data sits inside a customer's Customer Data, we will refer your request to that customer, who controls it. You also have the right to complain to your local data-protection authority.
11.Cookies
We use strictly necessary cookies to run the Service (for example, to keep you signed in) and, only with your consent, optional cookies for analytics. You can control non-essential cookies through your browser or any consent controls we present.
12.Children
The Service is intended for organizations and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13.Changes to this policy
We may update this policy. Material changes will be reflected by updating the effective date above and, where appropriate, by notifying you. Continued use of the Service after changes take effect means you accept the updated policy.
14.Contact
Questions or requests about privacy? Email privacy@erag.one.