Tannit.AI

Privacy policy

Tannit AI LLC · Horev 50, Haifa, Israel · Effective [[EFFECTIVE_DATE]]

This Privacy Policy describes the privacy practices of Tannit AI LLC (“Tannit AI,” “we,” “us” or “our”) and how we handle personal information that we collect through our website at tannit.org, our products, our online services and other digital properties that link to this Privacy Policy (collectively, the “Service”), as well as through our marketing activities and other activities described in this Privacy Policy. If you are located in the European Economic Area (the “EEA”) or the United Kingdom (the “UK”), please consult the Notice to European users below.

Index

1. Personal information we collect

When you use our Services or communicate with us, we may collect certain personal information about you. This section describes the types of personal information we may collect, and the ways in which we collect it.

Information you provide to us

Automatic data collection

If you use our Services, we may automatically log information about you, your computer or mobile device, and your interactions with us over time, such as your IP address.

Cookies and similar technologies

Some of our automatic data collection is facilitated by cookies and similar technologies:

2. How we use your personal information

For the personal information we collect about you as a controller, we may use such personal information for the following purposes or as otherwise described at the time of collection:

3. Customer content and model training

Prompts and completions submitted through our API are processed in memory for the duration of the request. We do not write prompt or completion content to persistent storage, we do not log it, and we do not inspect it. We do not use customer content to train, develop, fine-tune or improve any machine learning model, on any plan, whether paid or free, and we do not disclose customer content to any third party for that purpose. There is no opt-in.

Because we do not retain customer content, we are unable to locate, produce, restore or delete it in response to a request. Abuse detection is carried out using request metadata only — volume, timing, status codes and token counts — and never by inspecting content.

We retain aggregate token counts for billing, and operational metadata such as request timestamps, model identifier, status code and latency for a rolling [[RETENTION_DAYS]]-day period. We may use aggregated and anonymised usage data, which does not identify you or your content, for capacity planning, performance monitoring and abuse prevention.

As between you and Tannit, you retain all rights in the prompts you submit and own the completions returned to you to the extent they are capable of ownership.

4. How we share your personal information

For the personal information we collect about you as a controller, we may share such personal information with the following parties and as otherwise described in this Privacy Policy or at the time of collection.

We do not sell personal information.

5. Your choices

6. Other sites and services

The Services may contain links to third party websites and other online services operated by third parties. These links are not an endorsement of, or a representation that we are affiliated with, any third party. We do not control third-party services, we are not responsible for their actions, and they are not subject to this Privacy Policy. We encourage you to read the privacy policies of the other services you use.

7. Security

We employ technical, organisational and physical safeguards designed to protect the personal information we collect. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.

We take the security of our systems seriously and value the contributions of the security community. If you believe you have discovered a potential vulnerability, please email security@tannit.org with sufficient detail to help us reproduce and understand it. Please allow us a reasonable amount of time to investigate and resolve the issue before disclosing it publicly or to any third party, make a good-faith effort to avoid violating privacy, destroying data, or interrupting or degrading Tannit AI services, and interact only with accounts you own or for which you have explicit authorisation from the account holder.

8. International data transfer

We may use service providers that operate in other countries. Your personal information may be transferred to locations where privacy laws may differ from those in your state, province or country.

Users in the UK and the EEA should read the information provided in the Notice to European users below about transfers of personal data outside the EEA and UK.

9. Children

Our Services are not intended for use by children. If we learn that we have collected personal information through our Services from a child without the consent of the child's parent or guardian as required by law, we will delete it. We encourage parents or guardians with concerns to contact us.

10. Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by updating the date of this Privacy Policy and posting it on our Services. If required by law we will also provide notification in another way that we believe is reasonably likely to reach you. Any modifications will be effective upon posting the modified version, or as otherwise indicated at the time of posting. We recommend that you check this Privacy Policy periodically.

11. How to contact us

Email: privacy@tannit.org
Mail: Tannit AI LLC, Horev 50, Haifa, Israel

12. Notice to European users

12.1 Where this notice applies

The information in this section applies only to individuals in the United Kingdom and the European Economic Area, together referred to as “Europe”.

12.2 Personal information

References to “personal information” in this Privacy Policy should be understood to include a reference to “personal data” as defined in the GDPR — information about individuals from which they are either directly identified or can be identified. It does not include anonymous data, meaning information where the identity of the individual has been permanently removed.

12.3 Controller

Tannit AI is the controller in respect of the processing of your personal information covered by this Privacy Policy for the purposes of European data protection legislation, being the EU GDPR and the UK GDPR as applicable. See the section above for our contact details.

Article 27 representative. Tannit AI LLC is established in Israel. Our representative in the European Union for the purposes of Article 27 GDPR is [[EU_REPRESENTATIVE]].

12.4 Our legal bases for processing

In respect of each purpose for which we use your personal information, the GDPR requires us to have a legal basis for that use. Our legal bases are:

Purpose Categories of personal information Legal basis
Service delivery Contact information, sign-up information, account profile information, payment information, communications information, device information Contractual Necessity. Processing is necessary to perform the contract governing our provision of the services, or to take steps you request before signing up. If we have not entered into a contract with you, we process your personal information based on our legitimate interest in providing the services you access and request.
Research and development Any and all data types relevant in the circumstances Legitimate Interests. We have a legitimate interest in understanding what may be of interest to our customers, improving customer relationships and experience, delivering relevant content, and measuring the effectiveness of the content we serve.
Model training None. Customer content is not used for this purpose. Not applicable. We do not process personal information for model training.
Compliance and protection Any and all data types relevant in the circumstances Compliance with Law. Legitimate Interests. Where Compliance with Law does not apply, we and any relevant third parties have a legitimate interest in participating in, supporting and following legal process and requests, including through co-operation with authorities, and in ensuring the protection, maintenance and enforcement of our and their rights, property and safety.
Further uses Any and all data types relevant in the circumstances The original legal basis relied upon, if the relevant further use is compatible with the initial purpose for which the personal information was collected. Consent, if it is not compatible.

12.5 Retention

We retain personal information for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting or reporting requirements, to establish or defend legal claims, or for compliance and protection purposes. To determine the appropriate retention period we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal requirements.

When we no longer require the personal information we have collected about you, we will either delete or anonymise it or, if this is not possible — for example because it has been stored in backup archives — we will securely store it and isolate it from any further processing until deletion is possible. If we anonymise your personal information so that it can no longer be associated with you, we may use that information indefinitely without further notice to you.

12.6 Other information

No sensitive personal information. We ask that you do not provide us with sensitive personal information, such as national identification numbers, or information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometric or genetic characteristics, criminal background or trade union membership. If you provide such information to us, you must consent to our processing and use of it in accordance with this Privacy Policy. If you do not consent, you must not submit it through our Services.

No automated decision-making or profiling. As part of the Services, we do not engage in automated decision-making or profiling which produces legal or similarly significant effects.

12.7 Your rights

European data protection laws give you certain rights regarding your personal information. If you are located in Europe, you may ask us to take the following actions in relation to the personal information we hold about you:

12.8 Exercising these rights

To exercise any of these rights, contact us using the details above. We may request specific information from you to help us confirm your identity and process your request. Whether we are required to fulfil a request will depend on a number of factors, such as why and how we are processing your personal information. If we reject a request in whole or in part, we will tell you our grounds for doing so at the time, subject to any legal restrictions.

12.9 Your right to lodge a complaint

If you are not satisfied with our response to a request, or with how we process your personal information, you can complain to the data protection regulator in your habitual place of residence.

12.10 Data processing outside Europe

We, and many of our service providers, advisers, partners and other recipients of data, may be based outside your region. This means that if you use the Services your personal information may necessarily be accessed and processed internationally, and may be provided to recipients in countries outside Europe. Where we share your personal information with third parties based outside Europe, we seek to ensure a similar degree of protection through one of the following mechanisms:

You may contact us if you want further information on the specific mechanism used when transferring your personal information out of Europe.