Adaly AI Inc. ("Adaly," "we," "us") operates the website at adaly.ai and provides a federated data orchestration platform through our products Studio, Atlas, and Vessel (together, the "Services").
This policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have over it.
1. Two different roles
Our obligations depend on whose data is involved. We handle two categories very differently.
We are a controller for personal information we collect and decide the purpose of ourselves. This includes visitors to our website, prospects and marketing contacts, individual users who hold accounts on our Services, billing and vendor contacts, and job applicants. This policy governs that information.
We are a processor (a "service provider" under US state law) for personal information contained in the systems our customers connect to Adaly. Our customers decide which systems to connect, which queries run, and who is permitted to see results. We act on their documented instructions. That processing is governed by our Data Processing Agreement with the customer, not by this policy.
If your personal information sits inside a system that your employer or another organization connected to Adaly, contact that organization directly. We will refer your request to them.
2. Information we collect
Website visitors
- Device and connection data, including IP address, browser type, operating system, and referring page.
- Pages viewed, time on page, and interactions with the site.
- Information you submit through forms, including name, business email, company, job title, and the content of your message.
Prospects and marketing contacts
- Business contact details you provide to us or that we obtain from business contact data providers and public professional sources.
- Records of our communications with you, including emails, meeting notes and transcripts where you have been notified that a meeting is being recorded, and event interactions.
Users of the Services
- Account details, including name, business email, organization, role, and authentication identifiers.
- Configuration and connection settings for the systems your organization has authorized.
- Usage and audit logs, including queries issued, connectors invoked, permissions applied, and timestamps. These logs exist to support security, governance, and billing.
- Support requests and correspondence.
Customer data processed through the Services
Adaly is designed to query connected systems of record at the time of the request and return live values. We do not create persistent copies of source records in order to serve queries.
We do generate and retain operational metadata about connected systems. This includes schema structures, field and entity relationships, ontology mappings, and query history. This metadata is necessary for the Services to function. Where it contains or could reveal personal information, we handle it under the customer's Data Processing Agreement and apply the same access controls as customer data.
Job applicants
- Name, contact details, resume or CV, work history, education, and any information you choose to include in your application.
- Interview notes, assessment results, and references you provide.
- Work authorization status where required for the role.
- We do not ask for salary history where prohibited by law.
Billing
We use third party payment processors. Payment card details are collected and stored by those processors, not by us. We receive transaction records and billing contact information.
3. Why we use it and our legal bases
| Purpose | Legal basis under GDPR / UK GDPR |
|---|---|
| Providing, securing, and supporting the Services | Performance of a contract |
| Account administration and billing | Performance of a contract |
| Security monitoring, audit logging, fraud prevention | Legitimate interests |
| Product improvement and analytics | Legitimate interests, or consent where required for cookies |
| Marketing communications to business contacts | Legitimate interests, or consent where required |
| Recruitment and hiring | Legitimate interests, and steps prior to entering a contract |
| Legal, tax, and regulatory compliance | Legal obligation |
Under PIPEDA we rely on your consent, express or implied depending on the sensitivity of the information and the purpose. You may withdraw consent subject to legal and contractual restrictions.
We do not use customer data processed through the Services to train machine learning models for our own purposes or for the benefit of other customers.
4. Cookies and analytics
We use strictly necessary cookies to operate the site and keep sessions secure. These cannot be disabled.
We also use analytics and, where applicable, marketing cookies to understand site usage and measure campaign performance. Where required by law, we ask for your consent before setting these and you can change your choice at any time through the cookie banner or your browser settings.
We honor Global Privacy Control signals as an opt out of sale or sharing where state law requires it.
5. Who we share information with
- Service providers and subprocessors. Cloud hosting, security, analytics, CRM, communications, payment processing, and recruiting tools. They act on our instructions and are bound by written agreements. Our current subprocessor list is available on request.
- Customers. If you are a user of the Services, your organization can see your account and activity records.
- Professional advisors. Lawyers, accountants, auditors, and insurers, under confidentiality obligations.
- Corporate transactions. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction.
- Legal and safety. Where required by law, court order, or valid legal process, or to protect our rights, users, or the public. Where a request concerns customer data, we will notify the affected customer unless legally prohibited.
We do not sell personal information. We do not share personal information for cross context behavioral advertising as those terms are defined under the CCPA and CPRA. We have not done so in the preceding twelve months. We do not knowingly collect or sell the personal information of anyone under 16.
6. International transfers
We are based in the United States and our personnel and infrastructure are located in the United States and Canada. If you are in the European Economic Area, the United Kingdom, or Switzerland, your information may be transferred outside your jurisdiction.
Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may request a copy of the relevant safeguards by contacting us.
For Canadian residents, information may be processed in the United States and may be accessible to US courts and law enforcement under applicable law.
7. Retention
We keep personal information only as long as necessary for the purpose it was collected.
- Website analytics data: up to 26 months.
- Marketing contact records: until you opt out, or after a period of inactivity we determine to be reasonable.
- Account and audit log data: for the term of the customer agreement plus the period specified in that agreement.
- Job applicant data: 12 months after a hiring decision unless you consent to a longer period, or longer where required by law.
- Billing and tax records: as required by law, typically seven years.
Operational metadata generated by the Services is deleted or returned on customer instruction in accordance with the Data Processing Agreement.
8. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These include encryption in transit and at rest, role based access control, least privilege access, audit logging, credential management, background checks for personnel with production access, and periodic security review.
Our governance model is built so that access to connected systems is scoped, permissioned, and logged at the point of query. Customers control which systems are connected and which users and agents are authorized to reach them.
No system is completely secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant regulators as required by law.
9. Your rights
Everyone
You can ask us to access, correct, or delete your personal information, or ask questions about how we handle it. Contact us at contact@adaly.ai.
EEA, UK, and Switzerland
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, including profiling. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
You have the right to lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office.
We do not make decisions producing legal or similarly significant effects based solely on automated processing.
California and other US states
Depending on your state, you may have the right to know what personal information we collect and the purposes for it, to access and obtain a copy, to correct inaccuracies, to delete it, to opt out of sale, sharing, or targeted advertising, to limit use of sensitive personal information, and to appeal a decision we make on your request.
We will not discriminate against you for exercising these rights.
To exercise a right, email contact@adaly.ai with the subject line "Privacy Rights Request." We will verify your identity before acting, typically by confirming information we already hold. An authorized agent may submit a request on your behalf with written authorization.
If we deny your request, you may appeal by replying to our decision. We will respond to the appeal within the period your state's law requires.
Canada
You may request access to your personal information and challenge its accuracy and completeness. You may withdraw consent subject to legal and contractual restrictions. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada. Ontario residents may also contact the Information and Privacy Commissioner of Ontario where applicable.
We respond to rights requests within the timelines set by applicable law, generally 30 days, and will tell you if we need an extension.
10. Marketing preferences
Every marketing email includes an unsubscribe link. You can also email us to opt out. We will still send you transactional and service messages related to your account.
11. Children
The Services are built for business use. We do not direct them to children and we do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We may update this policy. If we make a material change we will update the effective date above and, where appropriate, notify you by email or through the Services. Continued use of the Services after an update means you accept the revised policy.
13. Contact us
Adaly AI Inc.167 Madison Avenue, Suite 205 #1064
New York, NY 10016
United States
contact@adaly.ai
For customer data processing questions, contact your account team or refer to your Data Processing Agreement.