Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how Electryion ("we", "our" or "us") collects, uses, stores and shares personal data when you use the Electryion platform, website, and related services (the "Service"). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Dutch privacy law.
1. Who We Are
Electryion provides an AI workforce platform with specialized AI employees for small and medium businesses. When you use the Service, Electryion acts as the data controller for your account data, and as the data processor for the business data you feed into our AI employees (emails, candidate records, leads, requirements documents, tender briefs, and similar content).
For any privacy-related question, you can reach us at [email protected].
2. What Data We Collect
2.1 Data you provide directly
- Account information: name, email address, password hash, preferred language.
- Workspace information: company name, industry, team size, seat assignments.
- Agent preferences: onboarding answers, brand tone, target industries, communication style.
- Content you submit to AI employees: emails, drafts, candidate data, leads, requirements, tender briefs, notes.
- Payment information: handled by Stripe. We never store card numbers on our servers.
2.2 Data we receive from connected services
When you connect an external service (for example Google, Microsoft, or LinkedIn), we receive the data you authorize through OAuth, such as email messages, calendar events, or profile information. We only request the minimum scopes required for each AI employee to work.
Specifically for Google services, the scopes we request and the purpose of each are:
- openid, email, profile - to identify you, display your name and avatar, and link the connection to your Electryion account.
- gmail.send - only used after you explicitly press "Send" on a draft prepared inside Electryion. We never send mail without an explicit user action.
- calendar, calendar.events - so Axel can show your agenda for the day and create or update events you have approved.
- webmasters.readonly - used by the optional Google Search Console integration to read aggregated search performance data for your own properties.
Note: full Gmail inbox automation (reading, draft preparation, label management, and archive) is currently only available for Outlook accounts. Gmail support for these features will be enabled after Electryion completes Google's CASA Tier 2 security assessment. When that happens, Electryion will request additional scopes (gmail.readonly, gmail.modify, gmail.compose) through a renewed OAuth consent screen and this Privacy Policy will be updated accordingly.
2.2.1 Opt-in Sent-folder scanning (Promise Radar)
Axel includes an optional feature called Promise Radar that, when explicitly enabled by the user in agent settings, runs a once-daily background scan of the user's Sent folder over the previous 14 days. The scan extracts commitments the user made in outgoing messages (for example "I'll send the deck tomorrow") and surfaces them in the user's daily standup as reminders. The toggle is off by default; turning it off stops all future scans and existing extracted reminders can be dismissed by the user at any time. No Sent-folder content is shared with third parties beyond the LLM round-trip described in section 5.
2.3 Data collected automatically
- Technical data: IP address, browser type, device, operating system, and timestamps.
- Usage data: which features you use, which AI employees you interact with, error reports.
- Cookies and similar technologies: see our cookie disclosure on the banner at the bottom of the site.
3. How We Use Your Data
We use your data to:
- Provide and operate the Service, including running AI employees on your behalf.
- Personalize each AI employee to your preferences, language, and brand voice.
- Process payments, subscriptions and invoicing through Stripe.
- Send service, security and transactional emails.
- Detect abuse, prevent fraud and protect the integrity of the platform.
- Comply with legal obligations.
We do not use your business data (emails, requirements, candidate records, leads, tender briefs) to train AI models. Each workspace is isolated from other customers.
4. Legal Bases (GDPR)
We process your personal data under the following legal bases:
- Contract: to deliver the Service you signed up for.
- Legitimate interests: to secure, improve and monitor the platform.
- Consent: for optional cookies, marketing communications, and connected integrations.
- Legal obligation: to comply with accounting, tax and law-enforcement requirements.
5. Third-Party Processors
We share personal data only with vetted processors who help us run the Service. A comprehensive, up-to-date list including data location and purpose lives at https://electryion.com/sub-processors. In summary:
- Stripe (payments and billing).
- OpenAI and OpenRouter (large language models powering the AI employees; configured with zero data retention where supported).
- Microsoft (Outlook, Microsoft Calendar, OAuth - only after explicit user consent).
- Atlassian (Jira) and Linear (ticket import + write-back of approved EARS requirements for PRISM, only after OAuth consent).
- LinkedIn, Meta (Facebook, Instagram), and X (formerly Twitter) (social posting on Talon's behalf, only after OAuth consent).
- Hunter.io and Apify (optional lead enrichment and public web research, only when the customer triggers the action).
- Sentry (error monitoring, configured with PII redaction).
- Cloudflare (DNS, DDoS protection, privacy-friendly analytics).
- Hosting provider (Sevalla, with data centers inside the EU).
Google Workspace integration (Gmail, Google Calendar) is currently disabled while Electryion completes Google's CASA Tier 2 security assessment. We do not request Google scopes or process Google user data at this time. When the assessment completes, this Privacy Policy will be updated and existing users will be invited through a renewed OAuth consent screen before any Google data is processed.
All processors are bound by a Data Processing Agreement and commit to appropriate security safeguards.
6. International Transfers
Where a processor operates outside the European Economic Area, we rely on European Commission adequacy decisions or Standard Contractual Clauses to ensure your data is protected at an equivalent level.
7. How Long We Keep Your Data
- Account data: retained while your account is active and for up to 12 months after deletion, unless a longer period is legally required.
- Workspace content: deleted within 30 days after you delete your account or workspace.
- Billing records: retained for 7 years to comply with Dutch tax law.
- Audit logs: retained for up to 24 months for security investigations.
8. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data.
- Restrict or object to processing.
- Request data portability.
- Withdraw consent at any time.
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise any of these rights, email [email protected]. We respond within 30 days.
9. Security
We apply industry-standard security controls: TLS encryption in transit, encryption at rest for OAuth tokens, strict Content Security Policy headers, workspace-level data isolation, audit logging of sensitive actions, and bug-bounty reporting via [email protected].
10. Children
The Service is intended for businesses and is not directed at children under 16. If we learn that we have collected data from a child, we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in the app or by email. Continued use of the Service after an update constitutes acceptance of the revised policy.
13. Contact
Privacy questions: [email protected]
Security issues: [email protected]