Eleiris AI

Privacy Policy

Last updated: 17 June 2026

This privacy policy explains how Eleiris AI Oy handles personal data in connection with the Eleiris AI application and related services, including services integrated with Microsoft 365 and other customer-authorized systems. When Eleiris AI provides services to its customers, Eleiris AI may also process personal data on behalf of those customers. Such customer-controlled processing may be described in more detail in the customer's own privacy notices and data processing terms.

Data controller and contact information
Eleiris AI Oy (business ID: 3462797-9)
Email: privacy@eleiris.ai

Purposes and legal basis for processing personal data

We process personal data to provide, manage, secure, support, and develop Eleiris AI services. This includes user authentication and access management, ensuring service functionality and security, troubleshooting errors, customer support, and service analytics.

Service operation and security processing is primarily based on Eleiris AI's and its customers' legitimate interests in providing a secure and functional service. Where required, processing for service development, analytics, or optional features may be based on the user's consent.

Categories of personal data and sources

We may process the following categories of personal data:

We primarily receive personal data from users, customer administrators, customer-authorized identity providers and systems, and automatic service usage logs.

Microsoft 365 and third-party integrations

Eleiris AI may connect to Microsoft 365 or other third-party systems only when authorized by the customer, administrator, or user. Data accessed through such integrations is used to provide the requested Eleiris AI features, such as automation, search, summarization, categorization, workflow assistance, or meeting and communication support. Access is limited to the permissions granted for the integration and can be revoked according to the customer's or platform provider's controls.

Transfers and disclosures of personal data

Personal data may be disclosed to service providers that support the delivery of Eleiris AI services, such as cloud hosting, identity, monitoring, analytics, and communication service providers. These providers process personal data only as needed to provide their services to Eleiris AI or its customers.

We primarily process personal data within the European Union and the European Economic Area. If personal data is transferred outside the EU/EEA, we use appropriate safeguards required by applicable data protection law, such as adequacy decisions or standard contractual clauses where applicable.

Retention period

Personal data is retained for as long as necessary to provide the service, maintain customer relationships, comply with legal obligations, resolve disputes, enforce agreements, and maintain security and auditability. Users or customers may delete or request deletion of data where supported by the service and applicable law.

Data security

Eleiris AI uses technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. Measures may include access controls, authentication, encryption in transit, logging, monitoring, secure development practices, and least-privilege access to production systems.

Your rights

Subject to applicable data protection law, you may have the right to:

To exercise your rights or ask questions about personal data processing, contact us at privacy@eleiris.ai. If Eleiris AI processes your data on behalf of one of our customers, we may direct your request to the relevant customer as the data controller.

Automated decision-making

Personal data is not used for decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, unless separately agreed with the customer and permitted by applicable law.

Complaints

If you believe that the processing of your personal data violates applicable data protection legislation, you have the right to lodge a complaint with a supervisory authority. In Finland, the supervisory authority is the Data Protection Ombudsman: https://www.tietosuoja.fi.

Changes to this policy

We may update this privacy policy from time to time. The latest version will be available on this page.