Skip to main content

Privacy Policy

Effective September 6, 2026

Previous Versions

Introduction

At Elnora AI, we take privacy seriously. This Privacy Policy explains how Elnora AI, Inc. and its subsidiary Elnora AI OÜ (collectively, "Elnora," "we," "us," or "our") collect, use, disclose, and protect your personal information when you use our website (www.elnora.ai), our AI-powered protocol generation platform, and related services (collectively, the "Services").

This Policy applies to all individuals who interact with our Services, including visitors to our website, registered users, and business contacts. Please read this Policy carefully to understand our practices regarding your personal information.

Table of Contents

  1. Scope
  2. Information We Collect
  3. How We Use Your Information
  4. Cookies and Tracking Technologies
  5. How We Share Your Information
  6. Data Retention
  7. Data Security
  8. International Data Transfers
  9. Your Rights and Choices
  10. California Privacy Rights (CCPA/CPRA)
  11. European, UK, and Swiss Privacy Rights
  12. Children's Privacy
  13. AI and Model Training
  14. Changes to This Policy
  15. Contact Us

1. Scope

This Policy Applies To

  • Our website at www.elnora.ai
  • Our AI-powered protocol generation and optimization platform platform.elnora.ai
  • Communications with us via email, forms, or other channels
  • Marketing and promotional activities

This Policy Does NOT Apply To

  • Enterprise Customer Data: Where Elnora acts as a data processor on behalf of enterprise customers, the customer's privacy policy governs. Our processing of Enterprise Customer Data is governed by our Data Processing Addendum (DPA) and customer agreements, which include Standard Contractual Clauses (SCCs) for international data transfers. For questions about such data, please contact your organization's administrator or email us at privacy@elnora.ai to request our DPA.
  • Third-Party Services: Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties.

Regulatory Coverage

This Policy is designed to comply with:

  • EU General Data Protection Regulation (GDPR)
  • UK GDPR
  • Swiss Federal Act on Data Protection (FADP)
  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
  • Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25
  • Other applicable privacy laws

2. Information We Collect

Information You Provide Directly

CategoryExamples
Account InformationName, email address, company name, job title, password, phone number
Payment InformationBilling address and payment details. We use Stripe for payment processing and do not directly store your payment card information on our servers.
Protocol and Research DataLab protocols, experimental data, research parameters, and other scientific content you upload or input into our platform. Processed as Customer Data under the DPA where Elnora acts as processor (see §1).
CommunicationsSupport requests, feedback, survey responses, and correspondence with us
Marketing InformationDemo requests, newsletter signups, webinar registrations

Information Collected Automatically

CategoryExamples
Usage DataPages viewed, features used, actions taken, access times, referring URLs
Device InformationDevice type, operating system, browser type and version, device identifiers
Log DataIP address, browser settings, date/time of access, error logs
Location InformationGeneral location (city/country) derived from IP address
Measurement identifiers on a form submissionWhere we are measuring your visit, the pseudonymous analytics and session identifiers your browser is using, and the campaign you arrived by, recorded with the form you sent so that a booking can be counted back to its source (see Section 4)

Information From Third Parties

SourceData
SSO ProvidersName, email address, authentication tokens (when you sign in via Google Workspace or Microsoft Entra ID)
Analytics PartnersAggregated usage and interaction data
Business PartnersBusiness contact information from events or partnerships

Sensitive Data

In our role as controller for the data described in this Policy (account, marketing, website and support data), we do not request, require, or intentionally collect special category data or sensitive personal information. Where you upload protocols, experimental data, or other content to the platform, that content is Customer Data processed on your organisation's instructions under our Data Processing Addendum, where your organisation is the controller. If such content contains special category or sensitive data, it is handled under the DPA and the customer agreement, not this Policy.

3. How We Use Your Information

PurposeLegal basis
Providing ServicesTo perform our contract with you. Operate, maintain, and deliver our AI protocol generation platform.
Account ManagementTo perform our contract with you. Create and manage your account, process transactions.
Customer SupportTo perform our contract with you. Respond to inquiries, provide technical assistance.
Service ImprovementFor our legitimate interests in improving the reliability and quality of the platform for everyone who uses it. These interests are not overridden by your own, because improvement uses aggregated or anonymised data.
SecurityFor our legitimate interests in detecting and preventing fraud, abuse and security threats, to protect Elnora and its customers. Also to comply with our legal obligations where they apply.
Communications (transactional)To perform our contract with you. Service updates, technical notices, and administrative messages required to deliver the contracted service.
MarketingWith your consent, for marketing to people in the European Economic Area, the United Kingdom and Switzerland, and where California law requires it, except that we may send electronic marketing about our own similar products to existing customers on a soft opt-in basis where permitted by the law allows it, with an opt-out in every message.
Legal ComplianceTo comply with our legal obligations, including applicable laws, regulations, court orders and lawful government requests.
AnalyticsWith your consent, for the website analytics and advertising cookies in the European Economic Area, the United Kingdom, Switzerland, Quebec and wherever we cannot determine your location. We set those only after you accept on the banner, and you can withdraw at any time through the "Cookie choices" control in the footer. Everywhere else, and for the cookieless measurement described in Section 4 and for product analytics from your authenticated use of the platform, we rely on our legitimate interests in understanding aggregate usage to improve the Services, using privacy-preserving techniques (pseudonymisation after 90 days, deletion of usage logs at 12 months, no individual profiling).
Joining a booking to the campaign that produced itWith your consent where we ask before measuring, and elsewhere on our legitimate interests in knowing which of our marketing brings the people who go on to book a call, which the calendar itself cannot tell us. These interests are not overridden by your own, because the identifiers are ones your browser was already carrying, no new identifier is created, nothing further is disclosed about you, and the line is written only for visitors we are already measuring lawfully. The identifiers involved and how long they are kept are described in Section 4.

We Do NOT Use Your Data For

  • Training or fine-tuning our or any provider's AI models using your uploaded protocols or research data (see Section 13)
  • Selling your personal information, as "sale" is defined by applicable privacy law
  • Targeting advertising to you, on the platform or anywhere else, based on your protocols, research data or account activity
  • Uploading your contact details, in plain or hashed form, to advertising platforms, or building advertising audiences from sensitive categories

4. Cookies and Tracking Technologies

The platform sets no tracking cookies

platform.elnora.ai uses no analytics, advertising or tracking technologies. It sets no tracking cookies, no pixels and no web beacons, it does not fingerprint your device or track you across sites, and it is connected to no advertising platform. Product analytics are collected server-side from your authenticated use of the platform. Signing in requires two short-lived, strictly necessary cookies: sso_flow, which holds single sign-on state for ten minutes and is readable only by our sign-in endpoint, and providerSignin, which carries the result of a federated sign-in back to the application and is deleted as soon as it has been read. Neither is used for tracking, profiling, or cross-context behavioural advertising. The application also keeps your session token, your workspace preferences and a local cache of files you open in your browser's own storage, so that the product works; none of it is used for tracking or advertising.

The marketing website uses analytics and advertising cookies, and asks first where the law requires it

www.elnora.ai uses a small number of cookies to understand which pages are read, which sources bring people to the site, and which of our advertising leads to an enquiry. We may also use them to show our own ads to people who have already visited this website. Our Cookie Policy states whether we are currently doing so. Personalised advertising is switched off in our Google tag for every visitor, in every country, including those who accept everything.

Where the law requires consent before non-essential cookies are set, we ask first, and nothing non-essential is written until you answer. Visitors whose location we determine to be in the European Economic Area, the United Kingdom, Switzerland or Quebec see a banner offering analytics and advertising as two separate choices, with accepting and refusing given equal prominence and no box ticked in advance. Your answer is recorded in a strictly necessary cookie and holds for 180 days; within that period a refusal is never re-asked, and after it the banner asks again. Everywhere else, including the United States and the rest of Canada, we begin measuring when you arrive, and we rely on this notice and on your ability to turn it off, and the Cookie choices control in the footer of every page turns it off at any time. We determine location from your IP address at the moment of your request and do not store it for that purpose, and where we cannot determine it we show the banner and set nothing non-essential until you answer.

Every visitor is also counted by cookieless, aggregate measurement that neither stores nor reads anything on your device and uses no cookies or advertising identifiers. It continues for visitors who refuse and for browsers sending Global Privacy Control or Do Not Track, because it stores nothing on your device and reads nothing from it, and what those signals ask us to stop is tracking you and sharing information about you for advertising. It processes your IP address to produce aggregate traffic counts; we do not use it to identify you and we do not combine it with other data about you. We rely on our legitimate interests in knowing how much traffic our website receives, and you may object at any time by writing to privacy@elnora.ai.

CategoryPurposeTypical duration
Attribution (first party)Records the campaign parameters and advertising click identifiers in the link you arrived by, for example from a Google or LinkedIn ad, so we can tell which of our marketing actually worksUp to 90 days
AnalyticsDistinguishes visitors and sessions for aggregate traffic reportingUp to 2 years
Advertising (first party)Records which of our advertising brought you to the site, so we can tell which of our marketing works, and, where we have enabled it, lets us show our own ads to people who have already visited this websiteUp to 90 days

Our Cookie Policy lists every cookie we set and every analytics and advertising provider that receives data from this website, and is updated whenever that changes.

Joining a booking to the campaign that produced it

When you send us a form, the notification email that reaches our own inbox carries the pseudonymous identifiers your browser was already using: the analytics client and session identifiers, the identifier of your visit and how far into it you were, the page you started from, the role you selected, the campaign that first brought you, and, if you arrived by clicking one of our advertisements, the click identifier that advertisement carried. That identifier is what lets us tell the advertising platform which of the clicks it charged us for led to a booked call, rather than only that a campaign worked. They sit alongside the name, email address and company you typed.

Google Calendar tells us nothing when a call is confirmed, so that line is the only thing that lets a confirmed booking be counted back to the campaign that brought you. An automated job reads the line shortly after the email arrives, takes your email address from the message itself, and sends the confirmed booking to Google Analytics under the same pseudonymous identifier your visit used. Your name, email address and company are not sent, in plain or hashed form, to Google or to any other analytics or advertising provider.

This is a link between a pseudonymous identifier and a named person. It exists in our own inbox and in that job, and nowhere else. It is kept only as long as we keep the email, which Section 6 sets at no more than 3 years from your last interaction with us.

No identifier is written for a visitor we are not measuring, which includes anyone who refused, anyone we have not asked, and any browser sending Global Privacy Control or Do Not Track.

What we will not do

We do not sell your personal information. We do not upload customer lists, contact lists, or email addresses, in plain or hashed form, to advertising platforms. We do not use anything from platform.elnora.ai, including your protocols, research data or account activity, to target advertising at you, and we do not share it with advertising platforms. We do not build advertising audiences based on sensitive categories.

Your choices

We honour the Global Privacy Control (GPC) and Do Not Track (DNT) browser signals. If either is present, no banner is shown, no analytics, attribution or advertising cookie is set, anywhere in the world, regardless of your location, and you are not added to any advertising audience. A Cookie choices control sits in the footer of every page, in every country, so you can change your answer at any time, as easily as you gave it: it turns measurement on or off in one click, and turning it off deletes the analytics and advertising cookies already on your device. Where the banner is shown, it is the place the two purposes are offered separately, and refusing one there deletes only that purpose's cookies. You can also clear or block cookies in your browser at any time, or write to privacy@elnora.ai; the website works normally without them.

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

Service Providers (Subprocessors)

We use trusted third-party service providers to help us operate our business, including:

  • Cloud infrastructure and data hosting
  • AI model providers for protocol generation
  • AI request routing and gateway services
  • Payment processing
  • Product analytics

All service providers are contractually bound to protect your information and use it only for specified purposes.

For a complete and current list of subprocessors, visit our Trust Center. Enterprise customers with Data Processing Addendums may have specific notification rights as outlined in their agreements.

Analytics and Advertising Partners (marketing website only)

For www.elnora.ai we share limited measurement data with analytics and advertising providers: pages viewed, the source or campaign that referred you, and the fact that a form was submitted or a booking begun. We do not send your name, email address, or any other contact detail to these providers, in plain or hashed form.

These providers may use that data to report on our website traffic, to tell us which of our advertising produced an enquiry, and to show our ads to people who have visited this website. Some act as independent controllers of the data once it reaches them, under their own advertising data-processing terms, and where we run an advertising pixel we and its provider are joint controllers for the collection and transmission of what it sends. Our current providers are listed in our Cookie Policy.

Where you send us a form and we later confirm a booking, we tell Google Analytics that the booking happened, matched to your visit by the pseudonymous identifier described in Section 4. Nothing you typed and no contact detail is sent with it.

Nothing from platform.elnora.ai is shared with any advertising or analytics provider. Visitors in the European Economic Area, the United Kingdom, Switzerland and Quebec are included in the Google Analytics and Google Ads part of this sharing only if they accept on the banner, and anyone who refuses, in any country, along with any browser sending Global Privacy Control or Do Not Track, is excluded from it. The cookieless measurement described in Sections 4 and 8 is the exception: it continues for every visitor, and for anyone who has not answered or who refused it also records that a form was submitted or a booking begun; a browser sending Global Privacy Control or Do Not Track is counted by the page count alone.

Other Disclosures

CircumstanceDescription
Legal RequirementsWhen required by law, court order, or government request
Rights ProtectionTo enforce our terms, protect our rights, or ensure safety
Business TransfersIn connection with a merger, acquisition, or sale of assets, in which case we will provide notice (for example, by email or prominent website notice) of any change in the controller of your personal information and of any choices you may have
With Your ConsentWhen you have given us permission

6. Data Retention

We retain your personal information only as long as necessary for the purposes described in this Policy.

Data TypeRetention Period
Account InformationDuration of your account plus 60 days for account recovery, then deletion. Where required by law or for legitimate legal claims, specific records may be retained for up to 3 years from the date of the relevant transaction or event.
Customer/Protocol DataCustomer Data is retained for the duration of the contract. On contract termination, Elnora permanently deletes Customer Data, including backup copies, within 30 days, except where and only for as long as retention is required by applicable law or to establish, exercise, or defend legal claims, as set out in our Data Processing Addendum (§12). Customer Data processed on a customer's behalf is governed by the DPA; the deletion timeline mirrors DPA §12.2. You may export your data through the platform's self-service functionality during the contract term and the 30-day deletion window.
Payment Records7 years from the date of the transaction, in accordance with US federal and state tax and accounting requirements (including IRS recordkeeping rules and Utah state tax law). VAT/sales-tax records for EU/UK transactions are retained for the period required by the applicable member state or HMRC (minimum 6 years for UK VAT records).
Usage/Analytics DataUsage logs are pseudonymised within 90 days and the pseudonymised logs are deleted 12 months after collection. Aggregate data that has been irreversibly anonymised (no longer personal data) is retained indefinitely for product improvement. The copy held by our website analytics provider is governed by that provider's own retention setting, which we set to the shortest period it offers for the reporting we need, currently 14 months, after which it deletes the visitor-level records and keeps aggregate reports.
Measurement line in a form notificationKept in the notification email a form submission sends to our own inbox, read back by an automated job shortly after it arrives, and deleted with that email no later than 3 years from your last interaction with us.
Marketing PreferencesUntil you unsubscribe or request deletion, and no longer than 3 years from the date of your last interaction with our marketing communications.
Support Communications3 years from the date of resolution of the relevant support request, then deletion.

When retention periods expire, we securely delete or anonymize your data.

7. Data Security

We implement robust technical, organizational, and administrative security measures to protect your information:

  • Encryption: Industry-standard encryption for data at rest and in transit
  • Access Controls: Role-based access control with principle of least privilege
  • Authentication: Multi-factor authentication for privileged access
  • Monitoring: Security monitoring and logging
  • Audits: Regular security assessments and penetration testing
  • Compliance: Elnora holds an ISO/IEC 27001:2022 certification and a SOC 2 Type 2 attestation. Audit reports are available on request under standard confidentiality terms.

Visit our Trust Center for current compliance status and security documentation.

While we take extensive measures to protect your information, no method of transmission over the Internet or electronic storage is completely secure. You are responsible for keeping your account credentials confidential. This does not reduce our own obligations to protect your personal information under applicable data-protection law.

Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will:

  • Notify the relevant supervisory authority without undue delay and, where the law requires it, within 72 hours of becoming aware of the breach
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • Provide information about the nature of the breach, the data affected, and steps we are taking to mitigate harm
  • Offer guidance on protective measures you can take

To report a suspected security incident, contact us at security@elnora.ai.

8. International Data Transfers

Elnora AI, Inc. is headquartered in the United States. Our primary infrastructure is hosted on Amazon Web Services (AWS) in the United States.

Data Location

Customer data is primarily stored and processed in AWS data centers located in the United States. AI model providers may process data in their respective data center locations to provide real-time responses.

Transfer Mechanisms

For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States and other countries without an EU / UK adequacy decision, we rely on the following transfer tools:

  • EEA transfers — EU Standard Contractual Clauses (Module 2 / Module 3) per EU Commission Implementing Decision (EU) 2021/914, with the competent EU member-state supervisory authority (see §11.1).
  • UK transfers — the UK International Data Transfer Addendum to the EU SCCs (UK Addendum, B1.0, in force 21 March 2022), with the UK Information Commissioner's Office (ICO) as the competent supervisory authority.
  • Swiss transfers — the EU Standard Contractual Clauses with the amendments recognised by the FDPIC for transfers subject to the Swiss FADP (GDPR references read as references to the FADP, and the FDPIC named as the competent supervisory authority), with the Swiss Federal Data Protection and Information Commissioner (FDPIC) as the competent authority.
  • Website analytics, Google — for the marketing website only, data reaches Google LLC in the United States. We rely on the EU-US Data Privacy Framework and its UK Extension, and on the Swiss-US Data Privacy Framework, where the recipient is certified, and on the Standard Contractual Clauses above where it is not. Our Cookie Policy names what it receives. This transfer happens for a visitor in the EEA, the UK or Switzerland only after they accept on the cookie banner.
  • Website analytics, Vercel — for the marketing website only, data reaches Vercel Inc. in the United States for every visitor, including those who have not answered the banner, those who refused it, and browsers sending Global Privacy Control or Do Not Track. It receives the page requested, the referrer, an approximate location derived from your IP address, and a pseudonymous value that resets every day; for every visitor except one whose browser sends Global Privacy Control or Do Not Track, it also receives which conversion link was pressed and the page it was pressed from, and that a form was submitted or a booking begun. This transfer does not rest on your consent. We rely on our legitimate interests in knowing how much traffic our website receives, as described in Section 4, and on the same Data Privacy Framework and Standard Contractual Clauses above.
  • Supplementary measures — encryption at rest (AES-256) and in transit (TLS 1.2+), access controls, audit logging, no-training contractual prohibitions on AI sub-processors, and the further measures described in our Transfer Impact Assessment.

A completed Transfer Impact Assessment covering EEA, UK, and Swiss transfers is available to enterprise customers on request via privacy@elnora.ai.

Data Controllers

RegionControllerAddress
United StatesElnora AI, Inc.48 South Rio Grande Street, Salt Lake City, UT 84101
EU/UKElnora AI OÜHarju maakond, Saue vald, Laagri alevik, Vesiroosi tn 6, 76401, Estonia

Elnora AI OÜ is also the controller for visitors to www.elnora.ai in the European Economic Area and the United Kingdom, including the consent recorded when they answer the cookie banner.

9. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

RightDescriptionResponse Time
AccessRequest a copy of the personal information we hold about you, including the categories of data, purposes, recipients, and retention periods.30 days (extendable by a further 60 days for complex requests, with notice)
CorrectionRequest correction of inaccurate or incomplete information.30 days
DeletionRequest deletion of your personal information, subject to legal retention obligations.30 days
PortabilityReceive your data in a structured, machine-readable format (CSV or JSON) and transfer it to another controller where technically feasible.30 days
RestrictionRequest that we limit processing of your information (e.g., while accuracy is contested).30 days
ObjectionObject to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. Where processing is for direct marketing, you may object at any time and we will stop without any balancing test.30 days
Withdraw ConsentWithdraw consent at any time where processing is based on consent. Withdrawal does not affect lawfulness of prior processing.Immediate effect on future processing
Lodge a ComplaintLodge a complaint with your local supervisory authority (EU DPA, ICO, or FDPIC — see Section 11).N/A

Automated Decision-Making

Elnora does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you. Our AI-generated protocol outputs are recommendations that require human review and approval by the scientist or researcher using the platform. No solely automated decision-making with legal or similarly significant effects is applied to you as an individual.

How to Exercise Your Rights

  • Email: privacy@elnora.ai (preferred — fastest response)
  • Support: support@elnora.ai
  • Mail:
    • US: 48 South Rio Grande Street, Salt Lake City, UT 84101
    • EU: Vesiroosi tn 6, 76401 Laagri, Estonia

We will respond to your request within 30 calendar days of receipt of a verifiable request (or within the shorter period required by applicable law, such as 45 days for CCPA/CPRA). For complex or numerous requests, we may extend by a further 60 days (GDPR) or 45 days (CCPA/CPRA) with written notice. We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.

Marketing Communications

You can opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link in our marketing emails
  • Contacting us at privacy@elnora.ai
  • Updating your communication preferences in your account settings

10. California Privacy Rights (CCPA/CPRA)

California residents have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

10.1 Notice at Collection

At or before the time of collection, California residents are entitled to know the categories of personal information collected and the purposes for which it will be used. The categories we collect and the purposes are described in Sections 2 and 3 of this Policy. Whether we share personal information for cross-context behavioural advertising depends on which advertising features we have enabled. Our Cookie Policy states what is currently enabled and is updated before any change takes effect. We do not sell personal information. How long we keep each category is set out in Section 6, and how to opt out of sharing is set out in Section 10.5.

10.2 California Privacy Rights Summary

RightDescription
Right to KnowRequest disclosure of: (a) the categories and specific pieces of personal information collected; (b) the categories of sources; (c) the business or commercial purpose; (d) the categories of third parties with whom information is shared. Covers the 12-month period preceding your request.
Right to DeleteRequest deletion of personal information, subject to exceptions (e.g., completion of a transaction, legal obligation, security).
Right to CorrectRequest correction of inaccurate personal information.
Right to Opt-Out of Sale or SharingWe do not sell personal information. We share limited website measurement data with advertising providers, and where we have enabled personalised advertising we may use it to show our ads to people who have visited www.elnora.ai, which California treats as sharing. Our Cookie Policy states what is currently enabled. You may opt out at any time: we process opt-out preference signals including the Global Privacy Control in a frictionless manner (see Section 10.5), and a browser sending one receives no advertising cookie and enters no advertising audience. You may also email privacy@elnora.ai. Nothing from the platform is ever shared for advertising.
Right to Limit Use of Sensitive Personal InformationCalifornia residents may direct us to limit the use and disclosure of sensitive personal information to purposes necessary to provide the Services. We do not use sensitive personal information for purposes beyond those permitted by CPRA § 1798.121 without consent.
Right to Non-DiscriminationWe will not discriminate against you for exercising any of your CCPA/CPRA rights.

10.3 Authorized Agent

Authorized agents may submit requests on a California resident's behalf at privacy@elnora.ai with written authorization signed by the resident or a power of attorney. We may verify the resident's identity directly.

10.4 How to Exercise California Rights

Submit requests to privacy@elnora.ai with the subject line "California Privacy Request." We will respond within 45 calendar days of receipt; we may extend by a further 45 days with written notice. We will not charge a fee for a first request in any 12-month period.

10.5 Opt-out preference signals

We process opt-out preference signals, including the Global Privacy Control (GPC), in a frictionless manner. We do not charge you a fee, change your experience of the website, or show you any notification, pop-up or interstitial in response to the signal. A browser sending the signal receives no analytics, attribution or advertising cookie and enters no advertising audience, anywhere in the world.

To send an opt-out preference signal, use a browser or browser extension that supports the Global Privacy Control. A current list is maintained at https://globalprivacycontrol.org

You may also opt out through the Cookie choices control at the bottom of every page, which turns measurement off and deletes the cookies already on your device, or by emailing privacy@elnora.ai.

11. European, UK, and Swiss Privacy Rights

UK GDPR is a distinct legal order from the EU GDPR following the United Kingdom's exit from the European Union. The Swiss Federal Act on Data Protection (FADP) is likewise distinct. The substantive rights below apply across all three regimes; the supervisory authority and any complaint route depend on where you are located.

11.1 EEA — EU GDPR

If you are located in the European Economic Area, the EU GDPR applies to our processing of your personal data. Your competent supervisory authority is the data protection authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A directory is maintained by the European Data Protection Board: List of EU Supervisory Authorities.

11.2 United Kingdom — UK GDPR + Data Protection Act 2018

If you are located in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply. Your competent supervisory authority is the UK Information Commissioner's Office (ICO) at https://ico.org.uk. Cross-border transfers from the UK to non-adequate countries (including the United States) are made under the UK International Data Transfer Addendum to the EU SCCs (see Section 8 — Transfer Mechanisms).

11.3 Switzerland — FADP

If you are located in Switzerland, the revised Swiss Federal Act on Data Protection (FADP) applies. Your competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch.

We process your personal data based on:

  • Contract Performance — to provide our Services to you
  • Legitimate Interests — for business operations, security, service improvement, and the cookieless website measurement described in Section 4
  • Consent — for marketing communications, and for the website analytics and advertising cookies we ask about in the European Economic Area, the United Kingdom, Switzerland, Quebec, and wherever we cannot determine your location
  • Legal Obligation — to comply with applicable laws

11.5 Your Rights Across All Three Regimes

In addition to the rights in Section 9, you have the right to:

  • Lodge a Complaint with your local data protection supervisory authority (EU DPA, ICO, or FDPIC as applicable)
  • Data Portability — receive your data in a structured format and transfer it to another controller

11.6 EU and UK Representative

EU establishment and point of contact

Elnora AI OÜ is established in the European Union (Estonia) and is the controller for EU and UK personal data (see Section 8). Because Elnora has an establishment in the Union, a separate EU representative is not required for EU processing. EU data subjects may contact Elnora AI OÜ at the address below or at privacy@elnora.ai for all EU GDPR matters.

Elnora AI OÜ Harju maakond, Saue vald, Laagri alevik, Vesiroosi tn 6, 76401, Estonia Phone: +372 51 96 51 96 Email: privacy@elnora.ai

UK representative

Elnora processes UK Authorized Users' personal data as a processor on behalf of UK-based customers under the UK GDPR. Elnora has no establishment in the United Kingdom and is in the process of appointing a representative in the United Kingdom, as UK law requires. Pending that appointment, and in any event within thirty (30) days of any of the following, Elnora will confirm its appointed UK representative: (a) the first UK individual creating a platform account, (b) the launch of UK-specific marketing, or (c) any UK behavioural monitoring activity. UK data subjects may contact privacy@elnora.ai for all UK GDPR matters.

12. Children's Privacy

Our Services are directed exclusively at professionals (scientists, researchers, and enterprise customers in the life sciences and pharmaceutical sectors) and are not intended for use by individuals under the age of 18 in any jurisdiction.

COPPA (US): We do not knowingly collect personal information from children under 13 years of age within the meaning of the Children's Online Privacy Protection Act (COPPA). Our platform requires account creation with verified professional credentials, which provides a functional barrier against use by children under 13.

EEA and UK: Where an information society service is offered directly to a child, consent is valid only if the child is at least 16 (or such lower age, not below 13, as the relevant EEA Member State has set) in the EEA, or at least 13 in the UK. Our Services are offered only to professionals via professional registration and are not directed at or offered to children, so this consent requirement does not arise.

If we become aware that we have collected personal information from anyone under 18, we will take prompt steps to delete such information. If you believe we have inadvertently collected information from a minor, please contact us at privacy@elnora.ai.

13. AI and Model Training

Customer Data is NOT Used for Model Training

Important: Elnora does NOT use your uploaded protocols, experimental data, or other customer content to train the underlying AI models. Your research data is never sent to AI providers for the purpose of training their foundation models.

How We Improve Our Product

While we do not train AI models on your data, we may use irreversibly anonymised and aggregated information to improve our Services. This includes:

  • Refining prompts and instructions that guide our AI agent
  • Improving tool descriptions and workflow configurations
  • Enhancing the overall user experience through product analytics

This product improvement process does not involve training or fine-tuning AI models. Your identifiable data is not used for these purposes.

How Our AI Works

  • We use third-party AI model providers (including but not limited to Anthropic, OpenAI (via Azure), and Google Cloud Platform / Gemini) via their business API services. The current authoritative list is published on the Trust Center and in DPA Schedule 3.
  • Your data is processed by these providers solely to generate responses for you in real-time
  • Under our business/commercial agreements with these providers, data submitted via their business APIs is not used to train their foundation models, and we impose no-training obligations on our AI sub-processors contractually (see Section 8). We maintain business accounts with all AI providers to ensure these data-protection terms apply.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • We will update the "Effective Date" at the top of this Policy
  • For material changes, including any change to our data-processing practices, we will provide notice as described above before the change takes effect. For customers under a Master Service Agreement or Order Form, such changes are governed by the change-control and notice provisions of those agreements and Section 1.5 of our Terms of Service, including at least 30 days' prior written notice and the right to terminate without penalty. Continued use after a material change takes effect does not waive any statutory data-protection right you hold, and where a change requires a lawful basis under applicable data-protection law we will obtain that basis separately.

We encourage you to review this Policy periodically.

DateWhat changed
6 September 2026A consent banner was introduced for the European Economic Area, the United Kingdom, Switzerland, Quebec and visitors whose location we cannot determine, so Section 3 now records consent alongside the existing legitimate-interests basis. Section 4 describes the banner, the footer control and, for the first time, the pseudonymous measurement identifiers carried on a form submission. The cookieless page count was extended to visitors sending Global Privacy Control or Do Not Track, having previously been withheld from them. Section 1 adds Quebec's Law 25 and Section 15 names the person in charge of the protection of personal information. The banner's second purpose is named advertising rather than advertising measurement, because it also covers showing our own ads to people who have already visited the site, and Sections 4 and 5 now record that where we run an advertising pixel we and its provider are joint controllers for what it collects and sends. The permissive wording about showing our own ads, published on 1 September 2026, is unchanged.

15. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

General Inquiries

Privacy Contact

  • Email: privacy@elnora.ai
  • Person in charge of the protection of personal information: Carmen Kivisild, Chief Executive Officer, reachable at privacy@elnora.ai. This is the role required by section 3.1 of Quebec's Law 25.

Support

Security Concerns

Mailing Addresses

United States (Headquarters) Elnora AI, Inc. 48 South Rio Grande Street Salt Lake City, UT 84101 USA

European Union / United Kingdom Elnora AI OÜ Harju maakond, Saue vald Laagri alevik, Vesiroosi tn 6 76401, Estonia

Trust Center

For detailed information about our security practices, compliance certifications, and data handling procedures, visit our Trust Center.

This Privacy Policy was last updated on September 6, 2026.