Home/Privacy
Privacy at Pilea
Pilea handles your customers’ words, so how we treat that data matters. Here’s the plain-language version — the full policy, in full legal detail, is one click away.
Policy last updated June 2026
Your data is never used to train AI models
We run a Zero-Data-Retention arrangement with our AI processing partners: content sent for AI processing is not retained or logged by those providers once the request completes, and is never used to train their models.
Everything is hosted in the EU
The application and database are hosted entirely within GDPR-compliant data centres in the European Union. If any data ever moves outside the EEA, we rely on safeguards such as the European Commission’s Standard Contractual Clauses.
You stay in control of your customers’ data
For the feedback and signals you ingest — Slack messages, support tickets, CRM contacts — you are the Data Controller and Pilea is only the Processor, acting under our Data Processing Agreement. You can delete your workspace data at any time from inside the app.
No ad-tech, no data selling
We do not sell personal data. Our marketing site uses cookieless analytics, and the app uses only the strictly necessary cookies needed to keep you signed in — which is why you have never seen a cookie banner here.
The details
- What personal data does Pilea collect?
- Account and profile data (name, business email, job title, company), workspace metadata such as priority weights and agent schedules, in-app usage data, security and audit logs, billing details, and anything you send us when you contact support. Raw credit card details are handled by our payment processor, never stored by us.
- Is Pilea a controller or a processor?
- Both, depending on the data. We are the Controller for website visitors, marketing leads, and the account, profile and usage data of your authorized users. For the customer signals you ingest into the platform — Slack messages, error reports, CRM contacts — you are the Controller and we act strictly as a Processor under our DPA.
- Does Pilea use AI, and what happens to the data?
- Yes. Pilea uses enterprise-grade LLM providers to analyze and prioritize feedback and to power its agentic layer. Those providers operate under strict Zero-Data-Retention agreements, so your content is not retained, logged or used for training. AI-generated summaries and recommendations may occasionally be inaccurate or incomplete, and a person at your organization stays responsible for deciding whether to act on them.
- Am I subject to automated decision-making?
- Pilea’s scoring and recommendations are automated, but they operate on aggregated, customer-controlled data and are designed to support human decisions. They do not produce legal or similarly significant effects on individuals under Article 22 of the GDPR.
- How long is data kept?
- Account and workspace data is retained for the duration of your active subscription, and you can delete workspace data at any time from within the application. In-app telemetry and logs are kept for the subscription period before being aggregated or deleted. Marketing data is kept until you opt out.
- What are my GDPR rights and how do I use them?
- You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Email support@pileainsights.com to exercise any of them. You can also lodge a complaint with your local Data Protection Authority — in Norway, that is Datatilsynet.
- Who are your subprocessors?
- We use subprocessors for hosting, authentication, AI processing, monitoring and payments, all bound by data protection agreements. A current, named list is maintained in our Data Processing Agreement and kept up to date as providers change.