Privacy Policy
Last updated: April 13, 2026
1. Introduction
Effara ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website, use our platform, or interact with our services.
Effara operates as a data processor on behalf of our customers (data controllers). This policy covers data we process as a data controller — for example, when you visit our website, create an account, or contact us directly.
2. Data We Collect
Information you provide
- Account information: name, email address, company name, and job title when you register or request a demo.
- Communications: messages you send through our contact forms, emails, or support channels.
- Payment information: billing details processed securely through our payment provider. We do not store card numbers.
Information collected automatically
- Usage data: pages visited, features used, session duration, and referral source.
- Device data: browser type, operating system, screen resolution, and IP address.
- Cookies: see our Cookie Policy for details.
3. How We Use Your Data
We use personal data to:
- Provide, maintain, and improve our platform and services.
- Respond to inquiries and provide customer support.
- Send transactional communications (e.g. account confirmations, security alerts).
- Send marketing communications where you have opted in. You can unsubscribe at any time.
- Analyze usage patterns to improve user experience and product development.
- Comply with legal obligations.
4. Legal Bases for Processing (GDPR)
We process personal data under the following legal bases:
- Contract performance: to deliver the services you have requested.
- Legitimate interest: to improve our products, prevent fraud, and ensure security.
- Consent: for marketing communications and non-essential cookies.
- Legal obligation: to comply with applicable laws and regulations.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Service providers: hosting, analytics, email delivery, and payment processing partners who act as sub-processors under appropriate data processing agreements.
- Legal authorities: when required by law or to protect our rights.
All sub-processors are bound by contractual obligations to process data only as instructed and to maintain appropriate security measures.
6. Data Retention
We retain personal data only as long as necessary to fulfil the purposes described in this policy, or as required by law. When data is no longer needed, we securely delete or anonymize it.
7. Data Transfers
Effara is built and hosted in Europe. Your data is stored and processed within the EU. We do not transfer personal data outside the European Economic Area without appropriate safeguards (such as Standard Contractual Clauses).
8. Your Rights
Under the GDPR, you have the right to:
- Access, correct, or delete your personal data.
- Restrict or object to processing.
- Data portability.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at privacy@effara.ai.
9. Security
We implement industry-standard technical and organizational measures to protect your data, including encryption at rest and in transit, role-based access controls, and regular security assessments. For more details, see our Security page.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
11. Contact
If you have questions about this Privacy Policy, contact us at privacy@effara.ai.