Introduction
At Elnora AI, we take privacy seriously. This Privacy Policy explains how Elnora AI, Inc. and its subsidiary Elnora AI OÜ (collectively, "Elnora," "we," "us," or "our") collect, use, disclose, and protect your personal information when you use our website (www.elnora.ai), our AI-powered protocol generation platform, and related services (collectively, the "Services").
This Policy applies to all individuals who interact with our Services, including visitors to our website, registered users, and business contacts. Please read this Policy carefully to understand our practices regarding your personal information.
Table of Contents
- Scope
- Information We Collect
- How We Use Your Information
- Cookies and Tracking Technologies
- How We Share Your Information
- Data Retention
- Data Security
- International Data Transfers
- Your Rights and Choices
- California Privacy Rights (CCPA/CPRA)
- European, UK, and Swiss Privacy Rights
- Children's Privacy
- AI and Model Training
- Changes to This Policy
- Contact Us
1. Scope
This Policy Applies To
- Our website at www.elnora.ai
- Our AI-powered protocol generation and optimization platform platform.elnora.ai
- Communications with us via email, forms, or other channels
- Marketing and promotional activities
This Policy Does NOT Apply To
- Enterprise Customer Data: Where Elnora acts as a data processor on behalf of enterprise customers, the customer's privacy policy governs. Our processing of Enterprise Customer Data is governed by our Data Processing Addendum (DPA) and customer agreements, which include Standard Contractual Clauses (SCCs) for international data transfers. For questions about such data, please contact your organization's administrator or email us at privacy@elnora.ai to request our DPA.
- Third-Party Services: Our Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties.
Regulatory Coverage
This Policy is designed to comply with:
- EU General Data Protection Regulation (GDPR)
- UK GDPR
- Swiss Federal Act on Data Protection (FADP)
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
- Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25
- Other applicable privacy laws
2. Information We Collect
Information You Provide Directly
| Category | Examples |
|---|---|
| Account Information | Name, email address, company name, job title, password, phone number |
| Payment Information | Billing address and payment details. We use Stripe for payment processing and do not directly store your payment card information on our servers. |
| Protocol and Research Data | Lab protocols, experimental data, research parameters, and other scientific content you upload or input into our platform. Processed as Customer Data under the DPA where Elnora acts as processor (see §1). |
| Communications | Support requests, feedback, survey responses, and correspondence with us |
| Marketing Information | Demo requests, newsletter signups, webinar registrations |
Information Collected Automatically
| Category | Examples |
|---|---|
| Usage Data | Pages viewed, features used, actions taken, access times, referring URLs |
| Device Information | Device type, operating system, browser type and version, device identifiers |
| Log Data | IP address, browser settings, date/time of access, error logs |
| Location Information | General location (city/country) derived from IP address |
| Measurement identifiers on a form submission | Where we are measuring your visit, the pseudonymous analytics and session identifiers your browser is using, and the campaign you arrived by, recorded with the form you sent so that a booking can be counted back to its source (see Section 4) |
Information From Third Parties
| Source | Data |
|---|---|
| SSO Providers | Name, email address, authentication tokens (when you sign in via Google Workspace or Microsoft Entra ID) |
| Analytics Partners | Aggregated usage and interaction data |
| Business Partners | Business contact information from events or partnerships |
Sensitive Data
In our role as controller for the data described in this Policy (account, marketing, website and support data), we do not request, require, or intentionally collect special category data or sensitive personal information. Where you upload protocols, experimental data, or other content to the platform, that content is Customer Data processed on your organisation's instructions under our Data Processing Addendum, where your organisation is the controller. If such content contains special category or sensitive data, it is handled under the DPA and the customer agreement, not this Policy.
3. How We Use Your Information
| Purpose | Legal basis |
|---|---|
| Providing Services | To perform our contract with you. Operate, maintain, and deliver our AI protocol generation platform. |
| Account Management | To perform our contract with you. Create and manage your account, process transactions. |
| Customer Support | To perform our contract with you. Respond to inquiries, provide technical assistance. |
| Service Improvement | For our legitimate interests in improving the reliability and quality of the platform for everyone who uses it. These interests are not overridden by your own, because improvement uses aggregated or anonymised data. |
| Security | For our legitimate interests in detecting and preventing fraud, abuse and security threats, to protect Elnora and its customers. Also to comply with our legal obligations where they apply. |
| Communications (transactional) | To perform our contract with you. Service updates, technical notices, and administrative messages required to deliver the contracted service. |
| Marketing | With your consent, for marketing to people in the European Economic Area, the United Kingdom and Switzerland, and where California law requires it, except that we may send electronic marketing about our own similar products to existing customers on a soft opt-in basis where permitted by the law allows it, with an opt-out in every message. |
| Legal Compliance | To comply with our legal obligations, including applicable laws, regulations, court orders and lawful government requests. |
| Analytics | With your consent, for the website analytics and advertising cookies in the European Economic Area, the United Kingdom, Switzerland, Quebec and wherever we cannot determine your location. We set those only after you accept on the banner, and you can withdraw at any time through the "Cookie choices" control in the footer. Everywhere else, and for the cookieless measurement described in Section 4 and for product analytics from your authenticated use of the platform, we rely on our legitimate interests in understanding aggregate usage to improve the Services, using privacy-preserving techniques (pseudonymisation after 90 days, deletion of usage logs at 12 months, no individual profiling). |
| Joining a booking to the campaign that produced it | With your consent where we ask before measuring, and elsewhere on our legitimate interests in knowing which of our marketing brings the people who go on to book a call, which the calendar itself cannot tell us. These interests are not overridden by your own, because the identifiers are ones your browser was already carrying, no new identifier is created, nothing further is disclosed about you, and the line is written only for visitors we are already measuring lawfully. The identifiers involved and how long they are kept are described in Section 4. |
We Do NOT Use Your Data For
- Training or fine-tuning our or any provider's AI models using your uploaded protocols or research data (see Section 13)
- Selling your personal information, as "sale" is defined by applicable privacy law
- Targeting advertising to you, on the platform or anywhere else, based on your protocols, research data or account activity
- Uploading your contact details, in plain or hashed form, to advertising platforms, or building advertising audiences from sensitive categories
4. Cookies and Tracking Technologies
The platform sets no tracking cookies
platform.elnora.ai uses no analytics, advertising or tracking technologies. It sets no tracking cookies, no pixels and no web beacons, it does not fingerprint your device or track you across sites, and it is connected to no advertising platform. Product analytics are collected server-side from your authenticated use of the platform. Signing in requires two short-lived, strictly necessary cookies: sso_flow, which holds single sign-on state for ten minutes and is readable only by our sign-in endpoint, and providerSignin, which carries the result of a federated sign-in back to the application and is deleted as soon as it has been read. Neither is used for tracking, profiling, or cross-context behavioural advertising. The application also keeps your session token, your workspace preferences and a local cache of files you open in your browser's own storage, so that the product works; none of it is used for tracking or advertising.
The marketing website uses analytics and advertising cookies, and asks first where the law requires it
www.elnora.ai uses a small number of cookies to understand which pages are read, which sources bring people to the site, and which of our advertising leads to an enquiry. We may also use them to show our own ads to people who have already visited this website. Our Cookie Policy states whether we are currently doing so. Personalised advertising is switched off in our Google tag for every visitor, in every country, including those who accept everything.
Where the law requires consent before non-essential cookies are set, we ask first, and nothing non-essential is written until you answer. Visitors whose location we determine to be in the European Economic Area, the United Kingdom, Switzerland or Quebec see a banner offering analytics and advertising as two separate choices, with accepting and refusing given equal prominence and no box ticked in advance. Your answer is recorded in a strictly necessary cookie and holds for 180 days; within that period a refusal is never re-asked, and after it the banner asks again. Everywhere else, including the United States and the rest of Canada, we begin measuring when you arrive, and we rely on this notice and on your ability to turn it off, and the Cookie choices control in the footer of every page turns it off at any time. We determine location from your IP address at the moment of your request and do not store it for that purpose, and where we cannot determine it we show the banner and set nothing non-essential until you answer.
Every visitor is also counted by cookieless, aggregate measurement that neither stores nor reads anything on your device and uses no cookies or advertising identifiers. It continues for visitors who refuse and for browsers sending Global Privacy Control or Do Not Track, because it stores nothing on your device and reads nothing from it, and what those signals ask us to stop is tracking you and sharing information about you for advertising. It processes your IP address to produce aggregate traffic counts; we do not use it to identify you and we do not combine it with other data about you. We rely on our legitimate interests in knowing how much traffic our website receives, and you may object at any time by writing to privacy@elnora.ai.
| Category | Purpose | Typical duration |
|---|---|---|
| Attribution (first party) | Records the campaign parameters and advertising click identifiers in the link you arrived by, for example from a Google or LinkedIn ad, so we can tell which of our marketing actually works | Up to 90 days |
| Analytics | Distinguishes visitors and sessions for aggregate traffic reporting | Up to 2 years |
| Advertising (first party) | Records which of our advertising brought you to the site, so we can tell which of our marketing works, and, where we have enabled it, lets us show our own ads to people who have already visited this website | Up to 90 days |
Our Cookie Policy lists every cookie we set and every analytics and advertising provider that receives data from this website, and is updated whenever that changes.
Joining a booking to the campaign that produced it
When you send us a form, the notification email that reaches our own inbox carries the pseudonymous identifiers your browser was already using: the analytics client and session identifiers, the identifier of your visit and how far into it you were, the page you started from, the role you selected, the campaign that first brought you, and, if you arrived by clicking one of our advertisements, the click identifier that advertisement carried. That identifier is what lets us tell the advertising platform which of the clicks it charged us for led to a booked call, rather than only that a campaign worked. They sit alongside the name, email address and company you typed.
Google Calendar tells us nothing when a call is confirmed, so that line is the only thing that lets a confirmed booking be counted back to the campaign that brought you. An automated job reads the line shortly after the email arrives, takes your email address from the message itself, and sends the confirmed booking to Google Analytics under the same pseudonymous identifier your visit used. Your name, email address and company are not sent, in plain or hashed form, to Google or to any other analytics or advertising provider.
This is a link between a pseudonymous identifier and a named person. It exists in our own inbox and in that job, and nowhere else. It is kept only as long as we keep the email, which Section 6 sets at no more than 3 years from your last interaction with us.
No identifier is written for a visitor we are not measuring, which includes anyone who refused, anyone we have not asked, and any browser sending Global Privacy Control or Do Not Track.
What we will not do
We do not sell your personal information. We do not upload customer lists, contact lists, or email addresses, in plain or hashed form, to advertising platforms. We do not use anything from platform.elnora.ai, including your protocols, research data or account activity, to target advertising at you, and we do not share it with advertising platforms. We do not build advertising audiences based on sensitive categories.
Your choices
We honour the Global Privacy Control (GPC) and Do Not Track (DNT) browser signals. If either is present, no banner is shown, no analytics, attribution or advertising cookie is set, anywhere in the world, regardless of your location, and you are not added to any advertising audience. A Cookie choices control sits in the footer of every page, in every country, so you can change your answer at any time, as easily as you gave it: it turns measurement on or off in one click, and turning it off deletes the analytics and advertising cookies already on your device. Where the banner is shown, it is the place the two purposes are offered separately, and refusing one there deletes only that purpose's cookies. You can also clear or block cookies in your browser at any time, or write to privacy@elnora.ai; the website works normally without them.
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
Service Providers (Subprocessors)
We use trusted third-party service providers to help us operate our business, including:
- Cloud infrastructure and data hosting
- AI model providers for protocol generation
- AI request routing and gateway services
- Payment processing
- Product analytics
All service providers are contractually bound to protect your information and use it only for specified purposes.
For a complete and current list of subprocessors, visit our Trust Center. Enterprise customers with Data Processing Addendums may have specific notification rights as outlined in their agreements.
Analytics and Advertising Partners (marketing website only)
For www.elnora.ai we share limited measurement data with analytics and advertising providers: pages viewed, the source or campaign that referred you, and the fact that a form was submitted or a booking begun. We do not send your name, email address, or any other contact detail to these providers, in plain or hashed form.
These providers may use that data to report on our website traffic, to tell us which of our advertising produced an enquiry, and to show our ads to people who have visited this website. Some act as independent controllers of the data once it reaches them, under their own advertising data-processing terms, and where we run an advertising pixel we and its provider are joint controllers for the collection and transmission of what it sends. Our current providers are listed in our Cookie Policy.
Where you send us a form and we later confirm a booking, we tell Google Analytics that the booking happened, matched to your visit by the pseudonymous identifier described in Section 4. Nothing you typed and no contact detail is sent with it.
Nothing from platform.elnora.ai is shared with any advertising or analytics provider. Visitors in the European Economic Area, the United Kingdom, Switzerland and Quebec are included in the Google Analytics and Google Ads part of this sharing only if they accept on the banner, and anyone who refuses, in any country, along with any browser sending Global Privacy Control or Do Not Track, is excluded from it. The cookieless measurement described in Sections 4 and 8 is the exception: it continues for every visitor, and for anyone who has not answered or who refused it also records that a form was submitted or a booking begun; a browser sending Global Privacy Control or Do Not Track is counted by the page count alone.
Other Disclosures
| Circumstance | Description |
|---|---|
| Legal Requirements | When required by law, court order, or government request |
| Rights Protection | To enforce our terms, protect our rights, or ensure safety |
| Business Transfers | In connection with a merger, acquisition, or sale of assets, in which case we will provide notice (for example, by email or prominent website notice) of any change in the controller of your personal information and of any choices you may have |
| With Your Consent | When you have given us permission |
6. Data Retention
We retain your personal information only as long as necessary for the purposes described in this Policy.
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of your account plus 60 days for account recovery, then deletion. Where required by law or for legitimate legal claims, specific records may be retained for up to 3 years from the date of the relevant transaction or event. |
| Customer/Protocol Data | Customer Data is retained for the duration of the contract. On contract termination, Elnora permanently deletes Customer Data, including backup copies, within 30 days, except where and only for as long as retention is required by applicable law or to establish, exercise, or defend legal claims, as set out in our Data Processing Addendum (§12). Customer Data processed on a customer's behalf is governed by the DPA; the deletion timeline mirrors DPA §12.2. You may export your data through the platform's self-service functionality during the contract term and the 30-day deletion window. |
| Payment Records | 7 years from the date of the transaction, in accordance with US federal and state tax and accounting requirements (including IRS recordkeeping rules and Utah state tax law). VAT/sales-tax records for EU/UK transactions are retained for the period required by the applicable member state or HMRC (minimum 6 years for UK VAT records). |
| Usage/Analytics Data | Usage logs are pseudonymised within 90 days and the pseudonymised logs are deleted 12 months after collection. Aggregate data that has been irreversibly anonymised (no longer personal data) is retained indefinitely for product improvement. The copy held by our website analytics provider is governed by that provider's own retention setting, which we set to the shortest period it offers for the reporting we need, currently 14 months, after which it deletes the visitor-level records and keeps aggregate reports. |
| Measurement line in a form notification | Kept in the notification email a form submission sends to our own inbox, read back by an automated job shortly after it arrives, and deleted with that email no later than 3 years from your last interaction with us. |
| Marketing Preferences | Until you unsubscribe or request deletion, and no longer than 3 years from the date of your last interaction with our marketing communications. |
| Support Communications | 3 years from the date of resolution of the relevant support request, then deletion. |
When retention periods expire, we securely delete or anonymize your data.
7. Data Security
We implement robust technical, organizational, and administrative security measures to protect your information:
- Encryption: Industry-standard encryption for data at rest and in transit
- Access Controls: Role-based access control with principle of least privilege
- Authentication: Multi-factor authentication for privileged access
- Monitoring: Security monitoring and logging
- Audits: Regular security assessments and penetration testing
- Compliance: Elnora holds an ISO/IEC 27001:2022 certification and a SOC 2 Type 2 attestation. Audit reports are available on request under standard confidentiality terms.
Visit our Trust Center for current compliance status and security documentation.
While we take extensive measures to protect your information, no method of transmission over the Internet or electronic storage is completely secure. You are responsible for keeping your account credentials confidential. This does not reduce our own obligations to protect your personal information under applicable data-protection law.
Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
- Notify the relevant supervisory authority without undue delay and, where the law requires it, within 72 hours of becoming aware of the breach
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Provide information about the nature of the breach, the data affected, and steps we are taking to mitigate harm
- Offer guidance on protective measures you can take
To report a suspected security incident, contact us at security@elnora.ai.
8. International Data Transfers
Elnora AI, Inc. is headquartered in the United States. Our primary infrastructure is hosted on Amazon Web Services (AWS) in the United States.
Data Location
Customer data is primarily stored and processed in AWS data centers located in the United States. AI model providers may process data in their respective data center locations to provide real-time responses.
Transfer Mechanisms
For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States and other countries without an EU / UK adequacy decision, we rely on the following transfer tools:
- EEA transfers — EU Standard Contractual Clauses (Module 2 / Module 3) per EU Commission Implementing Decision (EU) 2021/914, with the competent EU member-state supervisory authority (see §11.1).
- UK transfers — the UK International Data Transfer Addendum to the EU SCCs (UK Addendum, B1.0, in force 21 March 2022), with the UK Information Commissioner's Office (ICO) as the competent supervisory authority.
- Swiss transfers — the EU Standard Contractual Clauses with the amendments recognised by the FDPIC for transfers subject to the Swiss FADP (GDPR references read as references to the FADP, and the FDPIC named as the competent supervisory authority), with the Swiss Federal Data Protection and Information Commissioner (FDPIC) as the competent authority.
- Website analytics, Google — for the marketing website only, data reaches Google LLC in the United States. We rely on the EU-US Data Privacy Framework and its UK Extension, and on the Swiss-US Data Privacy Framework, where the recipient is certified, and on the Standard Contractual Clauses above where it is not. Our Cookie Policy names what it receives. This transfer happens for a visitor in the EEA, the UK or Switzerland only after they accept on the cookie banner.
- Website analytics, Vercel — for the marketing website only, data reaches Vercel Inc. in the United States for every visitor, including those who have not answered the banner, those who refused it, and browsers sending Global Privacy Control or Do Not Track. It receives the page requested, the referrer, an approximate location derived from your IP address, and a pseudonymous value that resets every day; for every visitor except one whose browser sends Global Privacy Control or Do Not Track, it also receives which conversion link was pressed and the page it was pressed from, and that a form was submitted or a booking begun. This transfer does not rest on your consent. We rely on our legitimate interests in knowing how much traffic our website receives, as described in Section 4, and on the same Data Privacy Framework and Standard Contractual Clauses above.
- Supplementary measures — encryption at rest (AES-256) and in transit (TLS 1.2+), access controls, audit logging, no-training contractual prohibitions on AI sub-processors, and the further measures described in our Transfer Impact Assessment.
A completed Transfer Impact Assessment covering EEA, UK, and Swiss
transfers is available to enterprise customers on request via
privacy@elnora.ai.
Data Controllers
| Region | Controller | Address |
|---|---|---|
| United States | Elnora AI, Inc. | 48 South Rio Grande Street, Salt Lake City, UT 84101 |
| EU/UK | Elnora AI OÜ | Harju maakond, Saue vald, Laagri alevik, Vesiroosi tn 6, 76401, Estonia |
Elnora AI OÜ is also the controller for visitors to www.elnora.ai in the European Economic Area and the United Kingdom, including the consent recorded when they answer the cookie banner.
9. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
| Right | Description | Response Time |
|---|---|---|
| Access | Request a copy of the personal information we hold about you, including the categories of data, purposes, recipients, and retention periods. | 30 days (extendable by a further 60 days for complex requests, with notice) |
| Correction | Request correction of inaccurate or incomplete information. | 30 days |
| Deletion | Request deletion of your personal information, subject to legal retention obligations. | 30 days |
| Portability | Receive your data in a structured, machine-readable format (CSV or JSON) and transfer it to another controller where technically feasible. | 30 days |
| Restriction | Request that we limit processing of your information (e.g., while accuracy is contested). | 30 days |
| Objection | Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. Where processing is for direct marketing, you may object at any time and we will stop without any balancing test. | 30 days |
| Withdraw Consent | Withdraw consent at any time where processing is based on consent. Withdrawal does not affect lawfulness of prior processing. | Immediate effect on future processing |
| Lodge a Complaint | Lodge a complaint with your local supervisory authority (EU DPA, ICO, or FDPIC — see Section 11). | N/A |
Automated Decision-Making
Elnora does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you. Our AI-generated protocol outputs are recommendations that require human review and approval by the scientist or researcher using the platform. No solely automated decision-making with legal or similarly significant effects is applied to you as an individual.
How to Exercise Your Rights
- Email: privacy@elnora.ai (preferred — fastest response)
- Support: support@elnora.ai
- Mail:
- US: 48 South Rio Grande Street, Salt Lake City, UT 84101
- EU: Vesiroosi tn 6, 76401 Laagri, Estonia
We will respond to your request within 30 calendar days of receipt of a verifiable request (or within the shorter period required by applicable law, such as 45 days for CCPA/CPRA). For complex or numerous requests, we may extend by a further 60 days (GDPR) or 45 days (CCPA/CPRA) with written notice. We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.
Marketing Communications
You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in our marketing emails
- Contacting us at privacy@elnora.ai
- Updating your communication preferences in your account settings
10. California Privacy Rights (CCPA/CPRA)
California residents have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
10.1 Notice at Collection
At or before the time of collection, California residents are entitled to know the categories of personal information collected and the purposes for which it will be used. The categories we collect and the purposes are described in Sections 2 and 3 of this Policy. Whether we share personal information for cross-context behavioural advertising depends on which advertising features we have enabled. Our Cookie Policy states what is currently enabled and is updated before any change takes effect. We do not sell personal information. How long we keep each category is set out in Section 6, and how to opt out of sharing is set out in Section 10.5.
10.2 California Privacy Rights Summary
| Right | Description |
|---|---|
| Right to Know | Request disclosure of: (a) the categories and specific pieces of personal information collected; (b) the categories of sources; (c) the business or commercial purpose; (d) the categories of third parties with whom information is shared. Covers the 12-month period preceding your request. |
| Right to Delete | Request deletion of personal information, subject to exceptions (e.g., completion of a transaction, legal obligation, security). |
| Right to Correct | Request correction of inaccurate personal information. |
| Right to Opt-Out of Sale or Sharing | We do not sell personal information. We share limited website measurement data with advertising providers, and where we have enabled personalised advertising we may use it to show our ads to people who have visited www.elnora.ai, which California treats as sharing. Our Cookie Policy states what is currently enabled. You may opt out at any time: we process opt-out preference signals including the Global Privacy Control in a frictionless manner (see Section 10.5), and a browser sending one receives no advertising cookie and enters no advertising audience. You may also email privacy@elnora.ai. Nothing from the platform is ever shared for advertising. |
| Right to Limit Use of Sensitive Personal Information | California residents may direct us to limit the use and disclosure of sensitive personal information to purposes necessary to provide the Services. We do not use sensitive personal information for purposes beyond those permitted by CPRA § 1798.121 without consent. |
| Right to Non-Discrimination | We will not discriminate against you for exercising any of your CCPA/CPRA rights. |
10.3 Authorized Agent
Authorized agents may submit requests on a California resident's behalf at privacy@elnora.ai with written authorization signed by the resident or a power of attorney. We may verify the resident's identity directly.
10.4 How to Exercise California Rights
Submit requests to privacy@elnora.ai with the subject line "California Privacy Request." We will respond within 45 calendar days of receipt; we may extend by a further 45 days with written notice. We will not charge a fee for a first request in any 12-month period.
10.5 Opt-out preference signals
We process opt-out preference signals, including the Global Privacy Control (GPC), in a frictionless manner. We do not charge you a fee, change your experience of the website, or show you any notification, pop-up or interstitial in response to the signal. A browser sending the signal receives no analytics, attribution or advertising cookie and enters no advertising audience, anywhere in the world.
To send an opt-out preference signal, use a browser or browser extension that supports the Global Privacy Control. A current list is maintained at https://globalprivacycontrol.org
You may also opt out through the Cookie choices control at the bottom of every page, which turns measurement off and deletes the cookies already on your device, or by emailing privacy@elnora.ai.
11. European, UK, and Swiss Privacy Rights
UK GDPR is a distinct legal order from the EU GDPR following the United Kingdom's exit from the European Union. The Swiss Federal Act on Data Protection (FADP) is likewise distinct. The substantive rights below apply across all three regimes; the supervisory authority and any complaint route depend on where you are located.
11.1 EEA — EU GDPR
If you are located in the European Economic Area, the EU GDPR applies to our processing of your personal data. Your competent supervisory authority is the data protection authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A directory is maintained by the European Data Protection Board: List of EU Supervisory Authorities.
11.2 United Kingdom — UK GDPR + Data Protection Act 2018
If you are located in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply. Your competent supervisory authority is the UK Information Commissioner's Office (ICO) at https://ico.org.uk. Cross-border transfers from the UK to non-adequate countries (including the United States) are made under the UK International Data Transfer Addendum to the EU SCCs (see Section 8 — Transfer Mechanisms).
11.3 Switzerland — FADP
If you are located in Switzerland, the revised Swiss Federal Act on Data Protection (FADP) applies. Your competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC) at https://www.edoeb.admin.ch.
11.4 Legal Bases for Processing
We process your personal data based on:
- Contract Performance — to provide our Services to you
- Legitimate Interests — for business operations, security, service improvement, and the cookieless website measurement described in Section 4
- Consent — for marketing communications, and for the website analytics and advertising cookies we ask about in the European Economic Area, the United Kingdom, Switzerland, Quebec, and wherever we cannot determine your location
- Legal Obligation — to comply with applicable laws
11.5 Your Rights Across All Three Regimes
In addition to the rights in Section 9, you have the right to:
- Lodge a Complaint with your local data protection supervisory authority (EU DPA, ICO, or FDPIC as applicable)
- Data Portability — receive your data in a structured format and transfer it to another controller
11.6 EU and UK Representative
EU establishment and point of contact
Elnora AI OÜ is established in the European Union (Estonia) and is the controller for EU and UK personal data (see Section 8). Because Elnora has an establishment in the Union, a separate EU representative is not required for EU processing. EU data subjects may contact Elnora AI OÜ at the address below or at privacy@elnora.ai for all EU GDPR matters.
Elnora AI OÜ Harju maakond, Saue vald, Laagri alevik, Vesiroosi tn 6, 76401, Estonia Phone: +372 51 96 51 96 Email: privacy@elnora.ai
UK representative
Elnora processes UK Authorized Users' personal data as a processor on behalf of UK-based customers under the UK GDPR. Elnora has no establishment in the United Kingdom and is in the process of appointing a representative in the United Kingdom, as UK law requires. Pending that appointment, and in any event within thirty (30) days of any of the following, Elnora will confirm its appointed UK representative: (a) the first UK individual creating a platform account, (b) the launch of UK-specific marketing, or (c) any UK behavioural monitoring activity. UK data subjects may contact privacy@elnora.ai for all UK GDPR matters.
12. Children's Privacy
Our Services are directed exclusively at professionals (scientists, researchers, and enterprise customers in the life sciences and pharmaceutical sectors) and are not intended for use by individuals under the age of 18 in any jurisdiction.
COPPA (US): We do not knowingly collect personal information from children under 13 years of age within the meaning of the Children's Online Privacy Protection Act (COPPA). Our platform requires account creation with verified professional credentials, which provides a functional barrier against use by children under 13.
EEA and UK: Where an information society service is offered directly to a child, consent is valid only if the child is at least 16 (or such lower age, not below 13, as the relevant EEA Member State has set) in the EEA, or at least 13 in the UK. Our Services are offered only to professionals via professional registration and are not directed at or offered to children, so this consent requirement does not arise.
If we become aware that we have collected personal information from anyone under 18, we will take prompt steps to delete such information. If you believe we have inadvertently collected information from a minor, please contact us at privacy@elnora.ai.
13. AI and Model Training
Customer Data is NOT Used for Model Training
Important: Elnora does NOT use your uploaded protocols, experimental data, or other customer content to train the underlying AI models. Your research data is never sent to AI providers for the purpose of training their foundation models.
How We Improve Our Product
While we do not train AI models on your data, we may use irreversibly anonymised and aggregated information to improve our Services. This includes:
- Refining prompts and instructions that guide our AI agent
- Improving tool descriptions and workflow configurations
- Enhancing the overall user experience through product analytics
This product improvement process does not involve training or fine-tuning AI models. Your identifiable data is not used for these purposes.
How Our AI Works
- We use third-party AI model providers (including but not limited to Anthropic, OpenAI (via Azure), and Google Cloud Platform / Gemini) via their business API services. The current authoritative list is published on the Trust Center and in DPA Schedule 3.
- Your data is processed by these providers solely to generate responses for you in real-time
- Under our business/commercial agreements with these providers, data submitted via their business APIs is not used to train their foundation models, and we impose no-training obligations on our AI sub-processors contractually (see Section 8). We maintain business accounts with all AI providers to ensure these data-protection terms apply.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Effective Date" at the top of this Policy
- For material changes, including any change to our data-processing practices, we will provide notice as described above before the change takes effect. For customers under a Master Service Agreement or Order Form, such changes are governed by the change-control and notice provisions of those agreements and Section 1.5 of our Terms of Service, including at least 30 days' prior written notice and the right to terminate without penalty. Continued use after a material change takes effect does not waive any statutory data-protection right you hold, and where a change requires a lawful basis under applicable data-protection law we will obtain that basis separately.
We encourage you to review this Policy periodically.
| Date | What changed |
|---|---|
| 6 September 2026 | A consent banner was introduced for the European Economic Area, the United Kingdom, Switzerland, Quebec and visitors whose location we cannot determine, so Section 3 now records consent alongside the existing legitimate-interests basis. Section 4 describes the banner, the footer control and, for the first time, the pseudonymous measurement identifiers carried on a form submission. The cookieless page count was extended to visitors sending Global Privacy Control or Do Not Track, having previously been withheld from them. Section 1 adds Quebec's Law 25 and Section 15 names the person in charge of the protection of personal information. The banner's second purpose is named advertising rather than advertising measurement, because it also covers showing our own ads to people who have already visited the site, and Sections 4 and 5 now record that where we run an advertising pixel we and its provider are joint controllers for what it collects and sends. The permissive wording about showing our own ads, published on 1 September 2026, is unchanged. |
15. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
General Inquiries
- Email: contact@elnora.ai
- Phone (US): +1 801 384 9988
- Phone (EU): +372 51 96 51 96
Privacy Contact
- Email: privacy@elnora.ai
- Person in charge of the protection of personal information: Carmen Kivisild, Chief Executive Officer, reachable at privacy@elnora.ai. This is the role required by section 3.1 of Quebec's Law 25.
Support
- Email: support@elnora.ai
Security Concerns
- Email: security@elnora.ai
Mailing Addresses
United States (Headquarters) Elnora AI, Inc. 48 South Rio Grande Street Salt Lake City, UT 84101 USA
European Union / United Kingdom Elnora AI OÜ Harju maakond, Saue vald Laagri alevik, Vesiroosi tn 6 76401, Estonia
Trust Center
For detailed information about our security practices, compliance certifications, and data handling procedures, visit our Trust Center.
This Privacy Policy was last updated on September 6, 2026.