Privacy policy
Tannit AI LLC · Horev 50, Haifa, Israel · Effective [[EFFECTIVE_DATE]]
This Privacy Policy describes the privacy practices of Tannit AI LLC (“Tannit AI,” “we,” “us” or “our”) and how we handle personal information that we collect through our website at tannit.org, our products, our online services and other digital properties that link to this Privacy Policy (collectively, the “Service”), as well as through our marketing activities and other activities described in this Privacy Policy. If you are located in the European Economic Area (the “EEA”) or the United Kingdom (the “UK”), please consult the Notice to European users below.
Index
- Personal information we collect
- How we use your personal information
- Customer content and model training
- How we share your personal information
- Your choices
- Other sites and services
- Security
- International data transfer
- Children
- Changes to this Privacy Policy
- How to contact us
- Notice to European users
1. Personal information we collect
When you use our Services or communicate with us, we may collect certain personal information about you. This section describes the types of personal information we may collect, and the ways in which we collect it.
Information you provide to us
- Contact information: your first and last name, business, email address, mailing address, professional title and company name, and phone number.
- Sign-up information: the username and password you set to establish an online account with us.
- Account profile information: your preferred language, your location (city or country), and any other information you add to your account profile.
- Communications information: information we exchange with you, including when you contact us with questions or feedback.
- Other information: information not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Automatic data collection
If you use our Services, we may automatically log information about you, your computer or mobile device, and your interactions with us over time, such as your IP address.
Cookies and similar technologies
Some of our automatic data collection is facilitated by cookies and similar technologies:
- Cookies: text files that websites store on a visitor's device to identify the browser or to store settings, helping you navigate between pages, remembering preferences, enabling functionality, and helping us understand usage patterns.
- Local storage technologies: technologies such as HTML5 that provide cookie-equivalent functionality but can store larger amounts of data on your device.
2. How we use your personal information
For the personal information we collect about you as a controller, we may use such personal information for the following purposes or as otherwise described at the time of collection:
- Service delivery. To provide, operate, maintain and improve the Services and our business; establish and maintain your user account; communicate with you, including by sending announcements, updates, security alerts, and support and administrative messages; understand your needs and interests, and personalise your experience with the Services and our communications; and provide support for the Services, and respond to your requests, questions and feedback.
- Research and development. To analyse and improve the Services and our business. As part of these activities, we may create aggregated, de-identified or anonymous data from personal information we collect. We may use this data and share it with third parties for our lawful business purposes.
- Compliance and protection. To comply with applicable laws, lawful requests and legal process, such as responding to subpoenas or requests from government authorities; protect our, your or others' rights, privacy, safety or property, including by making and defending legal claims; audit our internal processes for compliance with legal and contractual requirements; enforce the terms that govern the Services; and prevent, identify, investigate and deter fraudulent, harmful, unauthorised or illegal activity, including cyberattacks and identity theft.
- With your consent. In some cases we may specifically ask for your consent to collect, use or share your personal information, such as when required by law.
- Cookies and similar technologies. For the purposes outlined in the section above.
3. Customer content and model training
Prompts and completions submitted through our API are processed in memory for the duration of the request. We do not write prompt or completion content to persistent storage, we do not log it, and we do not inspect it. We do not use customer content to train, develop, fine-tune or improve any machine learning model, on any plan, whether paid or free, and we do not disclose customer content to any third party for that purpose. There is no opt-in.
Because we do not retain customer content, we are unable to locate, produce, restore or delete it in response to a request. Abuse detection is carried out using request metadata only — volume, timing, status codes and token counts — and never by inspecting content.
We retain aggregate token counts for billing, and operational metadata such as request timestamps, model identifier, status code and latency for a rolling [[RETENTION_DAYS]]-day period. We may use aggregated and anonymised usage data, which does not identify you or your content, for capacity planning, performance monitoring and abuse prevention.
As between you and Tannit, you retain all rights in the prompts you submit and own the completions returned to you to the extent they are capable of ownership.
4. How we share your personal information
For the personal information we collect about you as a controller, we may share such personal information with the following parties and as otherwise described in this Privacy Policy or at the time of collection.
- Service providers. Third parties that provide services on our behalf or help us operate the Services or our business, such as hosting, information technology, customer support, email delivery and website analytics.
- Professional advisors. Lawyers, auditors, bankers and insurers, where necessary in the course of the professional services they render to us.
- Authorities and others. Law enforcement, government authorities and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
- Business transferees. Acquirers and other relevant participants in business transactions, or negotiations and diligence for such transactions, involving a corporate divestiture, merger, consolidation, acquisition, reorganisation, sale or other disposition of all or any portion of the business or assets of, or equity interests in, Tannit AI, including in connection with a bankruptcy or similar proceedings.
We do not sell personal information.
5. Your choices
- Access or update your information. If you have registered for an account, you may review and update certain account information by logging in.
- Cookies. Most browsers let you remove or reject cookies by following the instructions in your browser settings. If you disable cookies, the Services may not work properly.
- Do Not Track. Some browsers can be configured to send “Do Not Track” signals. We currently do not respond to these or similar signals.
- Declining to provide information. We need to collect personal information to provide certain services. If you do not provide information we identify as required, we may not be able to provide those services.
6. Other sites and services
The Services may contain links to third party websites and other online services operated by third parties. These links are not an endorsement of, or a representation that we are affiliated with, any third party. We do not control third-party services, we are not responsible for their actions, and they are not subject to this Privacy Policy. We encourage you to read the privacy policies of the other services you use.
7. Security
We employ technical, organisational and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.
We take the security of our systems seriously and value the contributions of the security community. If you believe you have discovered a potential vulnerability, please email security@tannit.org with sufficient detail to help us reproduce and understand it. Please allow us a reasonable amount of time to investigate and resolve the issue before disclosing it publicly or to any third party, make a good-faith effort to avoid violating privacy, destroying data, or interrupting or degrading Tannit AI services, and interact only with accounts you own or for which you have explicit authorisation from the account holder.
8. International data transfer
We may use service providers that operate in other countries. Your personal information may be transferred to locations where privacy laws may differ from those in your state, province or country.
Users in the UK and the EEA should read the information provided in the Notice to European users below about transfers of personal data outside the EEA and UK.
9. Children
Our Services are not intended for use by children. If we learn that we have collected personal information through our Services from a child without the consent of the child's parent or guardian as required by law, we will delete it. We encourage parents or guardians with concerns to contact us.
10. Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by updating the date of this Privacy Policy and posting it on our Services. If required by law we will also provide notification in another way that we believe is reasonably likely to reach you. Any modifications will be effective upon posting the modified version, or as otherwise indicated at the time of posting. We recommend that you check this Privacy Policy periodically.
11. How to contact us
Email: privacy@tannit.org
Mail: Tannit AI LLC, Horev 50, Haifa, Israel
12. Notice to European users
12.1 Where this notice applies
The information in this section applies only to individuals in the United Kingdom and the European Economic Area, together referred to as “Europe”.
12.2 Personal information
References to “personal information” in this Privacy Policy should be understood to include a reference to “personal data” as defined in the GDPR — information about individuals from which they are either directly identified or can be identified. It does not include anonymous data, meaning information where the identity of the individual has been permanently removed.
12.3 Controller
Tannit AI is the controller in respect of the processing of your personal information covered by this Privacy Policy for the purposes of European data protection legislation, being the EU GDPR and the UK GDPR as applicable. See the section above for our contact details.
Article 27 representative. Tannit AI LLC is established in Israel. Our representative in the European Union for the purposes of Article 27 GDPR is [[EU_REPRESENTATIVE]].
12.4 Our legal bases for processing
In respect of each purpose for which we use your personal information, the GDPR requires us to have a legal basis for that use. Our legal bases are:
- Where we need to perform a contract we are about to enter into or have entered into with you (Contractual Necessity).
- Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests (Legitimate Interests).
- Where we need to comply with a legal or regulatory obligation (Compliance with Law).
- Where we have your specific consent to carry out the processing (Consent).
| Purpose | Categories of personal information | Legal basis |
|---|---|---|
| Service delivery | Contact information, sign-up information, account profile information, payment information, communications information, device information | Contractual Necessity. Processing is necessary to perform the contract governing our provision of the services, or to take steps you request before signing up. If we have not entered into a contract with you, we process your personal information based on our legitimate interest in providing the services you access and request. |
| Research and development | Any and all data types relevant in the circumstances | Legitimate Interests. We have a legitimate interest in understanding what may be of interest to our customers, improving customer relationships and experience, delivering relevant content, and measuring the effectiveness of the content we serve. |
| Model training | None. Customer content is not used for this purpose. | Not applicable. We do not process personal information for model training. |
| Compliance and protection | Any and all data types relevant in the circumstances | Compliance with Law. Legitimate Interests. Where Compliance with Law does not apply, we and any relevant third parties have a legitimate interest in participating in, supporting and following legal process and requests, including through co-operation with authorities, and in ensuring the protection, maintenance and enforcement of our and their rights, property and safety. |
| Further uses | Any and all data types relevant in the circumstances | The original legal basis relied upon, if the relevant further use is compatible with the initial purpose for which the personal information was collected. Consent, if it is not compatible. |
12.5 Retention
We retain personal information for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting or reporting requirements, to establish or defend legal claims, or for compliance and protection purposes. To determine the appropriate retention period we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal requirements.
When we no longer require the personal information we have collected about you, we will either delete or anonymise it or, if this is not possible — for example because it has been stored in backup archives — we will securely store it and isolate it from any further processing until deletion is possible. If we anonymise your personal information so that it can no longer be associated with you, we may use that information indefinitely without further notice to you.
12.6 Other information
No sensitive personal information. We ask that you do not provide us with sensitive personal information, such as national identification numbers, or information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometric or genetic characteristics, criminal background or trade union membership. If you provide such information to us, you must consent to our processing and use of it in accordance with this Privacy Policy. If you do not consent, you must not submit it through our Services.
No automated decision-making or profiling. As part of the Services, we do not engage in automated decision-making or profiling which produces legal or similarly significant effects.
12.7 Your rights
European data protection laws give you certain rights regarding your personal information. If you are located in Europe, you may ask us to take the following actions in relation to the personal information we hold about you:
- Access. Provide you with information about our processing of your personal information and give you access to it.
- Correct. Update or correct inaccuracies in your personal information.
- Delete your personal information where there is no lawful reason for us to continue storing or processing it, where you have successfully objected to processing, where we may have processed it unlawfully, or where we are required to erase it to comply with local law. We may not always be able to comply with a request for erasure for specific legal reasons, which will be notified to you at the time of your request.
- Portability. Port a machine-readable copy of your personal information to you or a third party of your choice, in certain circumstances. This right applies only to automated information for which you initially provided consent, or which we used to perform a contract with you.
- Restrict the processing of your personal information if you want us to establish its accuracy; where our use is unlawful but you do not want us to erase it; where you need us to hold it even though we no longer require it, so that you can establish, exercise or defend legal claims; or where you have objected to our use but we need to verify whether we have overriding legitimate grounds.
- Object to our processing where we are relying on legitimate interests, or those of a third party, and something about your particular situation makes you want to object on the grounds that it impacts your fundamental rights and freedoms.
- Withdraw consent. Where we use your personal information based on your consent, you have the right to withdraw that consent at any time. This will not affect the lawfulness of any processing carried out before you withdraw it.
12.8 Exercising these rights
To exercise any of these rights, contact us using the details above. We may request specific information from you to help us confirm your identity and process your request. Whether we are required to fulfil a request will depend on a number of factors, such as why and how we are processing your personal information. If we reject a request in whole or in part, we will tell you our grounds for doing so at the time, subject to any legal restrictions.
12.9 Your right to lodge a complaint
If you are not satisfied with our response to a request, or with how we process your personal information, you can complain to the data protection regulator in your habitual place of residence.
- European Economic Area: contact details for your national regulator are listed at edpb.europa.eu.
- United Kingdom: the Information Commissioner's Office, Water Lane, Wycliffe House, Wilmslow, Cheshire SK9 5AF. Telephone +44 303 123 1113. ico.org.uk/make-a-complaint.
12.10 Data processing outside Europe
We, and many of our service providers, advisers, partners and other recipients of data, may be based outside your region. This means that if you use the Services your personal information may necessarily be accessed and processed internationally, and may be provided to recipients in countries outside Europe. Where we share your personal information with third parties based outside Europe, we seek to ensure a similar degree of protection through one of the following mechanisms:
- Transfers to territories with an adequacy decision. We may transfer your personal information to countries or territories whose laws have been deemed to provide an adequate level of protection by the European Commission or the UK Government, as applicable.
- Transfers to territories without an adequacy decision. Where laws have not been deemed adequate, we may use specific appropriate safeguards designed to give personal information effectively the same protection it has in Europe, such as standard contractual clauses approved by the relevant authorities; or, in limited circumstances, we may rely on a derogation permitting the transfer despite the absence of an adequacy decision or appropriate safeguards, such as your explicit consent to that transfer.
You may contact us if you want further information on the specific mechanism used when transferring your personal information out of Europe.