PRIVACY POLICY

PRIVACY POLICY

© 2025 Embellics AI Limited

Embellics AI Limited (“Embellics,” “we,” “our,” “us”) is committed to protecting your privacy and ensuring that your personal data is handled securely and in compliance with the General Data Protection Regulation (GDPR) and Irish data protection laws.

This Privacy Policy explains how we collect, process, store, and protect personal data when you use our website, services, and our AI automation system (“Kara”).

1. Who We Are (Data Controller / Data Processor)

Website + general business: Embellics AI Limited acts as the Data Controller.

Kara system used by our clients: Embellics acts as a Data Processor, handling customer data on behalf of the client (controller).

Company Name: Embellics AI Limited
Company Number: 801582
Registered Address: 10 The Avenue, Grey Abbey View, Kildare, R51 NF86, Ireland
Email: admin@embellics.com

2. Personal Data We Collect

A. Website & Marketing Data

  • Name

  • Email

  • Phone number

  • IP address

  • Cookies, analytics, browsing behavior

  • Contact form information

B. Data Processed Through Kara (as Processor)

Processed strictly on behalf of our clients:

  • Customer name

  • Phone number

  • Email

  • Appointment details

  • Booking history

  • CRM-integrated data fields

  • Lead information for outbound calls

  • Voice recordings

  • Conversation transcripts

  • Payment links or payment intent data

  • Service history

C. Device & Technical Data

  • Browser type

  • Operating system

  • Usage logs

  • Time/date of interactions

3. How We Use Personal Data

We process data to:

  • Provide and operate Kara

  • Automate bookings, rescheduling, reminders, and cancellations

  • Support outbound calls for lead conversion

  • Deliver customer support

  • Improve our services

  • Analyze performance and usage

  • Provide analytics and marketing insights (website only)

  • Fulfil legal obligations

We do not train AI models on client data.

4. Lawful Basis for Processing

Under GDPR, we rely on:

  • Legitimate Interest – to operate our website and provide services

  • Contractual Necessity – to deliver Kara to our clients

  • Consent – for cookies and marketing opt-ins

  • Legal Obligation – where applicable

We take reasonable measures to protect your data from unauthorized access, disclosure, or alteration. However, no online service is entirely secure, and we cannot guarantee the absolute security of your information.

  1. Data Storage & Security

We use GDPR-compliant hosting and AI infrastructure providers located in the EU/EEA or governed by Standard Contractual Clauses (SCCs).

Security measures include:

  • Encryption in transit (TLS)

  • Encryption at rest

  • Access control and authentication

  • Data minimisation

  • Monitoring and logging

  • Regular audits

  • Firewall and network security

Call recordings and transcripts are stored on GDPR-compliant cloud infrastructure, and only temporarily retained by telephony/AI providers.

6. Data Retention

RWe retain data only for as long as necessary:

  • Kara conversation data: per client instruction

  • CRM-integrated data: per client instruction

  • Call recordings: per client retention policy

  • Analytics/cookies: per cookie settings

  • Website form submissions: up to 12 months

Clients may request deletion at any time.

7. Sharing of Personal Data

We may share data with:

  • GDPR-compliant telephony infrastructure providers

  • GDPR-compliant hosting and AI infrastructure providers

  • GDPR-compliant workflow automation systems

  • CRM systems chosen by our clients

  • Legal authorities (only when required)

We do not sell personal data.

8. International Data Transfers

Where transfers occur outside the EU/EEA, we use:

  • Standard Contractual Clauses (SCCs)

  • GDPR-approved safeguards

9. Your GDPR RightsYou have the right to:

  • Access your data

  • Correct your data

  • Delete your data

  • Restrict processing

  • Object to processing

  • Request portability

  • Withdraw consent

To exercise rights: admin@embellics.com

10. Cookies

We use Google Analytics, Meta Pixel, Framer Analytics, and other marketing cookies.
See our Cookie Policy for full details.

11. Contact for GDPR

Data Protection Contact: admin@embellics.com
(We do not currently appoint a separate Data Protection Officer.)

12. Changes to This Policy

We may update this policy; updates will be posted here.