PromptlyPromptlyPromptly
FeaturesPricingUse casesDocumentationBlog
Sign inStart free trial
FeaturesPricingUse casesDocumentationBlog
Sign inStart free trial
Legal

Privacy Policy

How we collect, isolate, and protect your data — in plain language.

Last updated · 13 August 2026
On this page
1. Who we are2. When we are the controller and when we are the processor3. What data we collect4. Why we use data, and our legal basis5. AI processing (bring your own key)6. Cross-session memory7. Sharing and sub-processors8. International transfers9. How long we keep data10. Your rights11. Complaints12. Security13. Cookies14. Children15. Changes to this policy16. Contact

01Who we are

The data controller for the personal data described in section 3.1 is:

ControllerLILLY 021 DOO NOVI SAD (Lilly021 d.o.o.)
Registered addressBulevar oslobođenja 30A, 21000 Novi Sad, Serbia
Company registration number21364096
Tax identification number (PIB)110570869
Telephone+381 21 301 9244
Privacy contactoffice@promptly-assistant.com

Use that address for any data protection matter: questions about this policy, a request about your own data, or a request for our Data Processing Agreement.

02When we are the controller and when we are the processor

Promptly is a platform our customers use to run assistants for their own visitors. That means there are two different situations, and your rights are exercised in different places:

(a) We are the controller for the personal data of our customers and their team members — the people who sign up for Promptly, log into a workspace and pay for it. This policy describes that processing, and you can contact us directly about it.

(b) We are the processor for the personal data of end users who talk to an assistant on our customer's website. There, our customer is the controller: they decide what the assistant does, what knowledge it uses and how long conversations are kept. We process that data only on their instructions.

If you are a website visitor who chatted with a Promptly-powered assistant and want your data accessed or deleted, contact the operator of that website — they are the controller. You may also contact us and we will route your request to them, or act on it where the controller instructs us to.

A Data Processing Agreement (DPA) covering situation (b) is available to our customers on request at office@promptly-assistant.com.

03What data we collect

3.1 Data about our customers (we are the controller)

  • Account data — name, work email address, company name, password (stored as a hash), and, if you sign in with a third-party identity provider, the identifiers that provider returns to us.
  • Workspace configuration — assistant settings, prompts, knowledge sources you connect, integrations, seat and module assignments.
  • Billing metadata from Paddle — subscription status, plan and modules, invoice references, country for tax purposes, and the last digits and type of the payment instrument. We never receive or store your full card number; payment details are collected and held by Paddle (see section 7).
  • Usage and technical data — message counts, token usage reported by your AI provider, session duration, feature usage, error and performance logs, IP address, browser and device type.
  • Support communications — messages you send us by email, contact form or in-app chat.

3.2 Data we process on behalf of our customers (we are the processor)

  • Conversation data — the messages exchanged between a website visitor and an assistant, and any information the visitor volunteers in that conversation.
  • Knowledge base content — documents, pages, catalogue data and other content our customer uploads or connects, which may itself contain personal data.
  • Conversation summaries and cross-session memory, where our customer has enabled that feature (see section 6).
  • Technical data about the conversation — timestamps, IP address for abuse prevention and rate limiting, and session identifiers.

3.3 API keys and secrets

The AI provider API keys and other credentials you store in Promptly are held encrypted at rest and are never returned in cleartext through our interface, our API, our logs or support channels. We treat them as your confidential material, not as personal data, and we do not use them for any purpose other than operating your assistant.

04Why we use data, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the service, creating and running your workspacePerformance of a contract (Art. 6(1)(b))
Processing payments and issuing invoices through PaddlePerformance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c))
Keeping accounts secure; rate limiting, abuse prevention, fraud detectionLegitimate interests (Art. 6(1)(f)) — protecting the service and its users
Diagnosing errors, monitoring performance, improving the productLegitimate interests (Art. 6(1)(f))
Transactional emails (account, security, entitlement and billing notices)Performance of a contract (Art. 6(1)(b))
Marketing emails and newslettersConsent (Art. 6(1)(a)) — opt-in where the law requires it, withdrawable at any time
Complying with legal, accounting and tax obligationsLegal obligation (Art. 6(1)(c))
Processing described in section 3.2We act on our customer's instructions; the customer determines the legal basis

We do not sell personal data, and we do not use conversation data to train AI models.

We do not carry out profiling or automated decision-making that produces legal effects or similarly significantly affects individuals.

Marketing email

We send transactional email — account, security, entitlement and billing notices — because we need to in order to run your subscription; you cannot unsubscribe from those while you have an account. Any marketing email, such as a product newsletter, is separate: we only send it with your consent, we ask for that consent as an opt-in wherever the law requires one, and every marketing message carries a one-click unsubscribe link. Withdrawing consent stops the marketing email and changes nothing else about your account.

05AI processing (bring your own key)

Conversations are processed by the AI provider you connect to your workspace — OpenAI, Anthropic, Google Gemini, GLM (Zhipu) or Kimi (Moonshot) — using your own API key, under your own agreement with that provider.

This has two consequences you should understand:

  • That provider processes the content of conversations according to its own terms and privacy policy, and its own data location and retention rules. Because the account is yours, that provider is not our sub-processor — the relationship is between you and them. You are responsible for choosing a provider whose terms fit your own obligations, and for concluding any DPA you need with them.
  • We do not send your conversations to any AI provider other than the one you select.

Knowledge base search — embedding generation and reranking — runs on our own infrastructure, not on a third-party AI API, regardless of which provider you connect.

06Cross-session memory

Where our customer enables it, an assistant may store short summaries of previous conversations so it can recognise a returning visitor and give more relevant answers. Memory entries expire based on a retention period the customer configures, and a visitor can request deletion of their memory data at any time.

Where a customer has not set a retention period, memory entries are kept only for as long as necessary for that purpose, and consistent with our security and legal obligations.

07Sharing and sub-processors

We do not sell personal data. We share it only with providers who help us run the service, and only as far as they need it. Each is bound by a contract that requires confidentiality and appropriate security.

Sub-processorPurpose
Paddle.com Market LtdPayments, subscription billing, invoicing and tax — acting as our reseller and Merchant of Record
DigitalOceanCloud hosting, managed databases, managed cache and object storage
Twilio SendGridTransactional email delivery

Where your data is hosted. We host Promptly with reputable third-party cloud infrastructure providers, who maintain their own physical and network security programmes.

If we add a sub-processor in future — for example a third-party identity provider for single sign-on, or an internal alerting tool that receives personal data — we will add it to this list before it starts processing your data.

We may also disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of our users or the public.

An up-to-date list of sub-processors is available on request, and we will give customers notice of material changes to it.

08International transfers

We are established in the Republic of Serbia, which is outside the European Union and the European Economic Area, and which is not covered by an EU adequacy decision. If you are in the EU/EEA or the UK, this means your personal data is transferred to a country outside those areas.

For those transfers we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with supplementary technical and organisational measures — including encryption in transit, encryption of secrets at rest, access controls and tenant isolation.

Some of our sub-processors may also process data outside the EU/EEA. Where they do, transfers rely on Standard Contractual Clauses or another mechanism permitted under Chapter V of the GDPR.

You can request information about the relevant transfer mechanism by contacting us.

09How long we keep data

DataRetention
Account and workspace dataFor as long as your account is active
Conversation dataFor the duration of the workspace's subscription, or a shorter period our customer configures
Cross-session memoryUntil the configured expiry, or until deletion is requested
Closed / deleted workspacesRetained in read-only form for 30 days, then permanently deleted
Invoices, payment records and tax documentsFor the period required by applicable Serbian accounting and tax law
Security and access logsFor as long as necessary for the purpose, and consistent with our security and legal obligations
Support correspondenceFor as long as necessary for the purpose, and consistent with our security and legal obligations

After the applicable period we delete or irreversibly anonymise the data, except where we must keep it to meet a legal obligation or to defend a legal claim.

10Your rights

If we are the controller (section 2(a)), you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten"), where no overriding obligation or legitimate ground applies;
  • restrict processing in certain circumstances;
  • object to processing based on our legitimate interests;
  • data portability — receive your data in a structured, commonly used, machine-readable format;
  • withdraw consent at any time, where processing is based on consent — this does not affect processing carried out before withdrawal.

To exercise any of these, email us at office@promptly-assistant.com. We will respond within one month as required by the GDPR, and in any event no later than the applicable statutory deadline. We may ask you to verify your identity before we act.

If we are the processor (section 2(b)), please direct your request to the website operator who runs the assistant. We will assist them in responding.

11Complaints

If you believe we have handled your personal data unlawfully, please tell us first — we would rather fix it directly. You also have the right to lodge a complaint with a supervisory authority: you may lodge it with the Serbian Commissioner for Information of Public Importance and Personal Data Protection, or with your local EEA supervisory authority.

12Security

We take security seriously and apply measures appropriate to the risk, including:

  • encryption in transit (TLS) for all traffic to and from the platform;
  • encryption of stored secrets, including your AI provider API keys, which are never exposed in cleartext;
  • disk-level encryption at rest of stored data, provided by our hosting providers;
  • tenant isolation — conversations, knowledge bases and analytics are not shared between workspaces;
  • role-based access control within workspaces;
  • restricted production access for our personnel, on a least-privilege basis and with strong authentication, reviewed when the team or infrastructure changes;
  • abuse prevention — rate limiting and IP-level controls;
  • logging of security-relevant events.

No system can be guaranteed absolutely secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority and affected customers as required by law and without undue delay.

If you believe you have found a security vulnerability in Promptly, we want to hear from you. Report it to office@promptly-assistant.com with a description, reproduction steps and your environment, and please give us reasonable time to investigate before disclosing publicly.

13Cookies

We use:

  • Essential cookies — to keep you signed in, maintain your session and protect against abuse. These are necessary for the service to work and cannot be switched off.
  • Preference cookies — to remember choices such as language and light/dark theme.

We do not use advertising cookies, and we do not use third-party analytics or tracking cookies. If we introduce any non-essential analytics in future, we will ask for your consent before setting those cookies.

You can block or delete cookies in your browser settings, but the service may not work correctly without the essential ones.

The widget we provide runs on our customers' websites. Whether that website uses additional cookies, and what consent it collects, is the responsibility of that website's operator.

14Children

Promptly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

15Changes to this policy

We may update this policy. For material changes we will notify customers by email or through the service before they take effect. The "Last updated" date above always reflects the current version.

16Contact

Email — privacy requests, DPA requests, data subject rights, security reportsoffice@promptly-assistant.com
Telephone+381 21 301 9244
PostLilly021 d.o.o., Bulevar oslobođenja 30A, 21000 Novi Sad, Serbia

We aim to respond within 2 business days, and in any case within the deadlines the GDPR sets for data subject requests.

See also our Terms of Service and Refund Policy.

PromptlyPromptlyPromptly

Your content. Your brand. One script tag.
Built with care for support teams everywhere.

Explore

  • Features
  • Pricing
  • Use cases

Company

  • About
  • Contact

Resources

  • Blog
  • Status

Legal

  • Privacy
  • Terms
  • Security
  • Refunds
© 2026 Lilly021 d.o.o. All rights reserved.Built with care for support teams everywhere.