Legal

Privacy Policy

Last updated 5 August 2026

1. Who we are

EITRI is the trading name of a sole trader business based in England ("EITRI", "we", "us", or "our"). We build AI agents and custom software for businesses and manage what we build under an optional monthly retainer.

For the personal information described in this policy, we are the data controller under UK data protection law (UK GDPR and the Data Protection Act 2018).

Questions, requests, or concerns: hello@eitri.so.

2. Who this policy covers

This policy covers:

  • Visitors to our website.
  • People who contact us or submit a form on the Site, including a demo request.
  • People at businesses we reach out to about our services.
  • Our clients and their team members we deal with during an engagement.

It does not cover the end users of systems we build or manage for our clients. If you are a customer, crew member, or contact of one of our clients and your details sit inside a system we built or manage, that data belongs to and is controlled by the client — see section 9. Questions about it should go to them.

3. Information we collect

Information you give us

  • Demo and contact form: your name, phone number, email address, whatever you tell us about what you need, and the fact and time of your consent to be contacted.
  • Messages: the content of your conversations with us and with our demo agent, by text, email, WhatsApp, or message. Conversations with the demo agent are processed by AI providers (see section 8) and kept so we can improve how our agents answer.
  • Engagement information: details about your business, your prices, your terms, your systems, and your requirements that you share with us so we can build for you.
  • Billing information: what we need to invoice you and take payment. Card details are handled by our payment provider, Stripe; we do not receive or store your full card details.

Information from other sources

We contact businesses that we think would benefit from our services. To do that, we collect business contact information from publicly available sources — such as company websites, public registers, and licensing databases. This is typically: business name, the name and role of the owner or a relevant contact, business email address, business phone number, and general information about the company.

Information collected automatically

The Site uses no analytics, advertising, or tracking tools, and sets no cookies of its own. Our hosting and network providers record standard server logs (such as IP address, browser type, and pages requested) for security and operation. If we add analytics or similar tools in future, we will update this section and section 16 before they are used.

4. How we use your information

  • To respond when you get in touch and to answer your questions.
  • To run the demo: to have one of our agents contact you by text and email, and to answer what you ask it.
  • To deliver engagements: building, delivering, and managing your agents and software, including under the retainer.
  • To send progress updates and test links during a build.
  • To review and improve how our agents answer, including correcting mistakes.
  • To invoice and take payment.
  • To contact businesses about our services (see section 6).
  • To keep records we need for legal, accounting, and tax purposes.
  • To protect our rights and the security of our systems.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

5. Legal bases (UK GDPR)

We rely on the following legal bases:

  • Performance of a contract — to deliver Services you've engaged us for, and to take steps you've asked for before entering a contract.
  • Consent — to send you the demo messages by text and email. You give it by ticking the box on the form, and you can withdraw it at any time (see section 15).
  • Legitimate interests — to run, promote, and improve our business, including contacting businesses about our services, reviewing agent conversations for quality, keeping business records, and securing our systems. When we rely on legitimate interests, we balance them against your rights, and you can object at any time (see sections 6 and 13).
  • Legal obligation — where we must keep or share information to comply with the law (such as tax and accounting records).

6. Outreach to businesses and your choices

We introduce ourselves to businesses by email and other business channels, using business contact details collected as described in section 3, and sent through our outreach provider (Instantly). Every message we send says who we are and gives you a simple way to opt out.

If you opt out, we stop. We keep the minimum needed (typically your email address) on a suppression list so we don't contact you again. If you'd rather we delete everything we hold about you instead, tell us and we will, unless we're required to keep something by law.

7. Who we share information with

We share personal information only with service providers who help us run the business and deliver what we built, under terms that protect it. The providers we currently use are:

  • Payments: Stripe.
  • CRM, forms, and workflow: GoHighLevel.
  • Outreach email: Instantly.
  • Transactional email: Resend.
  • Database and storage: Supabase.
  • Application hosting and background jobs: Railway, Trigger.dev.
  • Network, DNS, and security: Cloudflare.
  • AI model providers: OpenAI, Anthropic, and Google (see section 8).
  • Professional advisers (such as an accountant) where needed.

This list changes as our tooling changes; the current list is always here, and we will keep it updated. We may also disclose information where required by law, to protect our rights or others' safety, or as part of a transfer of the business — if the business is incorporated, sold, or reorganised, information may be transferred to the successor, and this policy will continue to apply to it.

8. AI providers, and what happens to what you type

Our agents are built on AI models provided by third parties, currently OpenAI, Anthropic, and Google. When you message our demo agent, or when an agent we built answers on a client's behalf, the content of that message is sent to one of those providers to generate the reply.

  • We use these providers through their business or API terms, under which your content is not used to train their models. We do not use it to train any model of our own either.
  • Providers may retain content briefly for abuse monitoring and security, in line with their own terms.
  • We do not knowingly send special category data (such as health information) to an AI provider, and you should not put it into a message to one of our agents.
  • Conversations are stored in our own database and we may read and review them for business purposes: correcting mistakes, improving how our agents answer, and running and supporting the service. We do not sell them and we do not use them to train AI models.

If we change AI provider, this section will be updated.

9. Client systems: when we process data on a client's behalf

When we build, host, run, or manage systems for a client — for example under the retainer — those systems contain personal data belonging to the client's business: their customers, leads, crew, contacts, and the conversations their agents have with them. For that data, the client is the controller and we act as their processor: we handle it only on the client's instructions, only to deliver the service, and we keep it confidential and secure. When an engagement ends or a client leaves the retainer, that data is handed over to the client and our access ends.

If your data is in one of those systems, the client's own privacy notice governs it, and requests about it should go to the client. We'll assist the client with such requests where needed.

10. International transfers

We are based in the United Kingdom. Our clients are largely in the United States, and most of our service providers store or process data there. Where personal information is transferred out of the UK, we rely on appropriate safeguards recognised under UK law, such as the UK International Data Transfer Agreement or Addendum, or transfers to countries covered by UK adequacy regulations. Details are available on request.

11. How long we keep information

  • Enquiries and demo requests: kept while we're in touch and for a reasonable period afterwards, then deleted.
  • Demo conversations: kept for up to 12 months so we can improve how our agents answer, then deleted.
  • Client records: kept for the engagement and afterwards for as long as the law requires (in the UK, typically six years for business, tax, and accounting records).
  • Outreach data: kept while relevant; suppression entries kept so we don't contact you again after an opt-out.

When we no longer need information, we delete or anonymise it.

12. Security

We use appropriate technical and organisational measures to protect personal information, including access controls, encryption in transit, and backups. No method of transmission or storage is completely secure, so we can't guarantee absolute security, but we work to protect what you share with us.

13. Your rights (UK and EEA)

Under UK data protection law, you have the right to: access the personal information we hold about you and get a copy; have inaccurate information corrected; have information deleted; object to processing based on legitimate interests, including objecting to direct marketing at any time (we will always stop marketing to you if you object); restrict processing in certain circumstances; withdraw consent where we rely on it; and data portability where applicable.

To exercise any of these, contact hello@eitri.so. We'll respond in line with the law, normally within one month, and we will not charge you or treat you differently for asking. If you're unhappy with how we've handled your information, you can complain to the UK Information Commissioner's Office (ico.org.uk). If you are in the EEA, you may also complain to your local data protection authority.

14. Your rights if you are in the United States

Most of the people we deal with are US businesses. Depending on the state you are in — including California, Colorado, Connecticut, Texas, Utah, and Virginia — you may have the right to know what personal information we hold about you and to receive a copy of it, to have it corrected, to have it deleted, to opt out of targeted advertising, the sale of personal information, or profiling with legal effects, and not to be discriminated against for exercising any of those rights.

  • We do not sell personal information and we do not share it for cross-context behavioural advertising or targeted advertising.
  • We do not profile people in ways that produce legal or similarly significant effects.
  • The categories of information we collect, why, and who we share them with are set out in sections 3, 4, and 7. We do not collect sensitive personal information for the purposes of inferring characteristics.

To make a request, email hello@eitri.so with the state you are in and what you would like. We will verify the request against the information we already hold and respond within the time the law allows (generally 45 days). An authorised agent may act for you if you give them written permission. If we refuse a request, you may appeal by replying to our decision, and we will respond to the appeal within the applicable period.

If you are in California, this policy also serves as our notice at collection: the categories of personal information we collect are identifiers (name, email, phone), commercial information (what you bought), internet activity (server logs), and the content of your communications with us; we use and disclose them for the purposes in section 4; and we retain them as set out in section 11.

15. Text messages and email: consent and opting out

We only text or email you about our Services if you asked us to, or ticked the consent box on our form, or you are a business we contacted as described in section 6.

  • In the normal course you get one text and one email, plus replies to whatever you send back.
  • Message and data rates may apply. Your carrier's charges are yours.
  • To stop texts: reply STOP to any message. Reply HELP for help.
  • To stop emails: click unsubscribe in any email, or email hello@eitri.so.
  • We do not sell or rent your phone number or email address, and agreeing to be contacted is never a condition of buying anything.

When we stop, we keep the minimum record needed to make sure we don't contact you again.

16. Cookies and analytics

The Site sets no analytics, advertising, or tracking cookies, and we run no analytics or advertising tools on it. Our network provider (Cloudflare) may set strictly necessary cookies for security and to keep the Site available. Because we use no tracking, we do not show a cookie consent banner. If that changes, this section will be updated first with what is used, why, and the choices you have, and we will ask for consent where the law requires it.

17. Children

Our Services are for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us their information, contact hello@eitri.so and we will delete it.

18. Changes to this policy

We may update this policy from time to time. When we do, we'll change the date at the top, and for material changes we'll provide a more prominent notice.

19. Contact

EITRI
hello@eitri.so
114A SILVERDALE AVENUE, WESTCLIFF-ON-SEA, SS0 9BD

Our Terms of Service govern the Services themselves.