Privacy Policy
Last Updated: June 18, 2026
EPILO.ONE handles personal data with a bias toward minimization, clear purpose, restricted access, and documented processing for website visitors, inquiry submitters, authenticated users, and client assessment workflows.
1. Controller and contact
EPILO.ONE is the controller for personal data collected through the public website, contact form, and direct business inquiries. For client engagements where EPILO.ONE processes personal data under a customer's instructions, the customer usually acts as controller and EPILO.ONE acts as processor under the applicable agreement or Data Processing Addendum.
Privacy, procurement, and data protection questions can be submitted through the contact form or raised during the assessment intake process.
2. Scope
This policy applies to epilo.one, contact-form submissions, authenticated workspace activity, CMS administration, and AI assessment workflows operated by EPILO.ONE. It does not apply to third-party websites or services that are linked from the site and controlled by another organization.
3. Personal data we collect
We may collect the following categories of data:
- Contact data: name, email address, company, role, website, team size, preferred next step, and inquiry content.
- Account data: Firebase Authentication identifiers, email address, display name, role, and sign-in state for authenticated users.
- Project and assessment data: business briefs, project metadata, generated reports, supporting text or CSV excerpts, and implementation notes submitted by authenticated users.
- Administrative content: CMS edits, page content updates, and admin user identifiers.
- Technical data: request metadata, browser and device information, IP-derived security context, and operational logs required to run and protect the service.
4. Purposes and lawful bases
We process personal data for the following purposes:
- Responding to inquiries and preparing assessments.
- Operating authenticated workspaces, dashboards, CMS tools, and AI assessment workflows.
- Producing requested reports, implementation guidance, and follow-up material.
- Protecting the site, enforcing access controls, diagnosing failures, and preventing abuse.
- Meeting legal, contractual, security, and recordkeeping obligations.
Where GDPR applies, the lawful bases may include performance of a contract, steps taken before entering a contract, legitimate interests in operating and securing the service, consent where requested, and compliance with legal obligations.
5. AI assessment data
Business briefs, supporting file excerpts, and generated reports submitted through authenticated Lab workflows may be processed by server-side AI services to produce the requested analysis. EPILO.ONE treats submitted material as operational context, not as public content. Users should avoid submitting unnecessary personal data, special-category data, secrets, or material they are not authorized to process.
6. Processors and subprocessors
EPILO.ONE uses service providers to host, secure, and operate the website and application. Current provider categories include cloud hosting, authentication, database storage, AI model processing, and contact-form email relay. The public DPA page lists the current baseline subprocessors. Engagement-specific subprocessors can be confirmed during procurement.
7. International transfers
Some providers may process data outside the country where the customer or visitor is located. Where applicable, EPILO.ONE relies on the safeguards offered by those providers, such as standard contractual clauses or equivalent transfer mechanisms.
8. Retention
Contact inquiries are retained for as long as needed to respond, manage the relationship, and keep reasonable business records. Authenticated workspace data, briefs, and reports are retained for the duration of the engagement or account lifecycle unless a different retention period is agreed. Operational logs are retained for security, diagnostics, and abuse prevention for a limited period based on platform configuration and business need.
9. Security measures
EPILO.ONE applies technical and organizational measures including HTTPS transport, hardened response headers, authenticated private routes, role-based administrative access, Firestore security rules, server-side handling of model credentials, scoped access to project data, and route-level noindex controls for private application pages.
No internet service can guarantee absolute security. EPILO.ONE designs controls to reduce risk, limit access, and make implementation responsibilities explicit.
10. Your rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, objection to certain processing, or withdrawal of consent. Requests can be made through the contact route. We may need to verify your identity before acting on a request.
11. Marketing and cookies
EPILO.ONE does not sell personal data. If marketing communication is introduced, it will include a clear opt-out route. The current public site does not rely on behavioral advertising cookies.
12. DPA and procurement requests
A Data Processing Addendum is available on request for engagements involving client data, personal data, uploaded material, authenticated workspace access, or AI implementation work. Procurement teams can request the DPA, subprocessor details, and security-control summaries through the contact route.
13. Changes
This policy may be updated as the service, subprocessors, or operating model changes. The "Last Updated" date reflects the latest published version.