Privacy Policy
Effective 1 July 2025 · Eliis OU (Estonia) & Eliis Ltd (United Kingdom)
1. Who We Are
Eliis is an AI memory layer for independent spa and wellness therapists. The platform is operated by Eliis OU (registered in Estonia) for Estonian users and Eliis Ltd (registered in the United Kingdom) for UK users. In this policy “Eliis”, “we”, “us” and “our” refers to the relevant entity for your jurisdiction.
Contact: privacy@eliis.space
2. Scope of This Policy
This Privacy Policy explains how we process personal data when:
- A therapist (“Operator”) creates an account and uses the Eliis platform;
- A client (“Data Subject”) completes a health intake form sent by a therapist;
- A visitor browses the Eliis marketing website (eliis.space).
This policy does not cover how therapists use client data collected through the platform — that is governed by the therapist's own privacy notice. Therapists act as independent data controllers for their client data; Eliis acts as a data processor on their behalf.
3. Legal Basis for Processing
We process personal data under the following legal bases as defined by Article 6 of the GDPR (and Article 6 of the UK GDPR):
- Contract performance — to provide the platform service to therapist subscribers;
- Legitimate interests — to operate, secure, and improve the platform, and for fraud prevention;
- Legal obligation — to comply with applicable laws including tax, accounting, and regulatory requirements;
- Consent — for optional communications such as product updates and early access newsletters.
Health data collected through client intake forms constitutes special category data under Article 9 of the GDPR. This data is processed under the basis of explicit consent, obtained through the dual-consent mechanism within the platform: treatment consent and data processing consent are recorded as two separate signed records.
4. Data We Collect
- Name, email address, business name, country, phone number;
- Subscription and billing information (processed by Flutterwave — we do not store card details);
- Platform usage logs, session activity, and authentication records.
- Health conditions, medications, allergies, contraindications;
- Date of birth, sex;
- Session notes, voice note transcripts, aftercare records;
- Treatment history and therapist observations;
- Consent records (treatment and GDPR data processing).
- IP address, browser type, pages visited (via Vercel Analytics — aggregated and anonymised);
- Email address if submitted via the Early Access form.
5. How We Use Your Data
- To provide, maintain, and improve the Eliis platform;
- To process subscription payments and send billing communications;
- To generate AI-assisted session notes and aftercare emails on behalf of therapists;
- To send service announcements and, where consented, product updates;
- To detect and prevent fraud, abuse, and security incidents;
- To comply with our legal obligations under Estonian and UK law;
- To respond to enquiries and support requests.
6. How We Protect Your Data
Client health data is treated as special category data and is subject to the following protections:
- Encrypted at rest: All health profiles and session notes are encrypted using AES-256 symmetric encryption before being written to the database. The encryption key is derived uniquely per therapist account using HKDF (RFC 5869). The raw key is never stored.
- Encrypted in transit: All connections use TLS 1.3. Data is never transmitted unencrypted.
- Server-side only: Decryption happens exclusively server-side within a controlled environment. Health data is never processed in the browser.
- Access controls: Database access is enforced through row-level security policies. Therapists can only access their own clients' data. Service role access is restricted to backend API routes.
- No third-party AI training: Client health data is not shared with, sold to, or used to train any AI provider or third-party service.
7. Data Sharing
We share personal data only with:
- Supabase (database and authentication infrastructure) — hosted in Frankfurt, EU. Subject to a Data Processing Agreement;
- Flutterwave (payment processing) — your payment data is processed by Flutterwave under their own privacy policy. We do not store card details;
- Anthropic / OpenAI (AI processing) — voice transcripts (not health profiles) are sent to these providers to generate session notes. Data is processed under their API terms and is not used to train their models;
- Twilio / Resend (communications) — used to send SMS intake links and email aftercare messages. Only the minimum data required is transmitted;
- Vercel (hosting and analytics) — aggregated, anonymised website analytics only.
We do not sell personal data to any third party. We do not share personal data for advertising purposes.
8. Data Retention
- Therapist account data — retained for the duration of the subscription plus 6 years (as required by professional insurance standards and applicable financial regulations);
- Client health data — retained for up to 6 years from the date of last session, consistent with UK and Estonian professional standards for health records;
- Website analytics — aggregated and anonymised; not subject to retention limits;
- Early access signups — retained until the user creates an account or requests deletion.
Upon account deletion, all data is removed within 30 days except where retention is required by law.
9. International Transfers
All data is hosted on Supabase infrastructure located in Frankfurt, Germany (EU). Data does not leave the EU except where AI processing providers (Anthropic, OpenAI) operate outside the EU. In those cases, transfers are governed by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by Article 46 of the GDPR.
For UK users, these safeguards are equivalent under the UK GDPR International Data Transfer Agreement (IDTA) framework.
10. Your Rights
Under the GDPR and UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you;
- Rectification — correct inaccurate data;
- Erasure — request deletion of your data where there is no lawful basis for continued processing;
- Restriction — restrict processing in certain circumstances;
- Portability — receive your data in a structured, machine-readable format;
- Object — object to processing based on legitimate interests;
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at privacy@eliis.space. We will respond within 30 days.
You also have the right to lodge a complaint with your supervisory authority: the Estonian Data Protection Inspectorate (www.aki.ee) or the UK Information Commissioner's Office (ico.org.uk).
11. Cookies
We use only essential cookies required for authentication (Supabase session tokens). We do not use advertising cookies, tracking pixels, or any third-party marketing cookies. Website analytics are provided by Vercel Analytics using anonymised, aggregated data — no cookies are set for analytics purposes.
12. Children
The Eliis platform is intended for use by adult spa therapists. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor's data has been submitted, contact us at privacy@eliis.space immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify therapist subscribers by email and in-platform notification at least 14 days before material changes take effect. The effective date at the top of this page will always reflect the most recent version.
14. Contact
Data protection enquiries:
privacy@eliis.space
Eliis OU · Tallinn, Estonia
Eliis Ltd · United Kingdom