

How we collect, isolate, and protect your data — in plain language.
Last updated · 13 August 2026The data controller for the personal data described in section 3.1 is:
| Controller | LILLY 021 DOO NOVI SAD (Lilly021 d.o.o.) |
|---|---|
| Registered address | Bulevar oslobođenja 30A, 21000 Novi Sad, Serbia |
| Company registration number | 21364096 |
| Tax identification number (PIB) | 110570869 |
| Telephone | +381 21 301 9244 |
| Privacy contact | office@promptly-assistant.com |
Use that address for any data protection matter: questions about this policy, a request about your own data, or a request for our Data Processing Agreement.
Promptly is a platform our customers use to run assistants for their own visitors. That means there are two different situations, and your rights are exercised in different places:
(a) We are the controller for the personal data of our customers and their team members — the people who sign up for Promptly, log into a workspace and pay for it. This policy describes that processing, and you can contact us directly about it.
(b) We are the processor for the personal data of end users who talk to an assistant on our customer's website. There, our customer is the controller: they decide what the assistant does, what knowledge it uses and how long conversations are kept. We process that data only on their instructions.
If you are a website visitor who chatted with a Promptly-powered assistant and want your data accessed or deleted, contact the operator of that website — they are the controller. You may also contact us and we will route your request to them, or act on it where the controller instructs us to.
A Data Processing Agreement (DPA) covering situation (b) is available to our customers on request at office@promptly-assistant.com.
The AI provider API keys and other credentials you store in Promptly are held encrypted at rest and are never returned in cleartext through our interface, our API, our logs or support channels. We treat them as your confidential material, not as personal data, and we do not use them for any purpose other than operating your assistant.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service, creating and running your workspace | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and issuing invoices through Paddle | Performance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c)) |
| Keeping accounts secure; rate limiting, abuse prevention, fraud detection | Legitimate interests (Art. 6(1)(f)) — protecting the service and its users |
| Diagnosing errors, monitoring performance, improving the product | Legitimate interests (Art. 6(1)(f)) |
| Transactional emails (account, security, entitlement and billing notices) | Performance of a contract (Art. 6(1)(b)) |
| Marketing emails and newsletters | Consent (Art. 6(1)(a)) — opt-in where the law requires it, withdrawable at any time |
| Complying with legal, accounting and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Processing described in section 3.2 | We act on our customer's instructions; the customer determines the legal basis |
We do not sell personal data, and we do not use conversation data to train AI models.
We do not carry out profiling or automated decision-making that produces legal effects or similarly significantly affects individuals.
We send transactional email — account, security, entitlement and billing notices — because we need to in order to run your subscription; you cannot unsubscribe from those while you have an account. Any marketing email, such as a product newsletter, is separate: we only send it with your consent, we ask for that consent as an opt-in wherever the law requires one, and every marketing message carries a one-click unsubscribe link. Withdrawing consent stops the marketing email and changes nothing else about your account.
Conversations are processed by the AI provider you connect to your workspace — OpenAI, Anthropic, Google Gemini, GLM (Zhipu) or Kimi (Moonshot) — using your own API key, under your own agreement with that provider.
This has two consequences you should understand:
Knowledge base search — embedding generation and reranking — runs on our own infrastructure, not on a third-party AI API, regardless of which provider you connect.
Where our customer enables it, an assistant may store short summaries of previous conversations so it can recognise a returning visitor and give more relevant answers. Memory entries expire based on a retention period the customer configures, and a visitor can request deletion of their memory data at any time.
Where a customer has not set a retention period, memory entries are kept only for as long as necessary for that purpose, and consistent with our security and legal obligations.
We are established in the Republic of Serbia, which is outside the European Union and the European Economic Area, and which is not covered by an EU adequacy decision. If you are in the EU/EEA or the UK, this means your personal data is transferred to a country outside those areas.
For those transfers we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with supplementary technical and organisational measures — including encryption in transit, encryption of secrets at rest, access controls and tenant isolation.
Some of our sub-processors may also process data outside the EU/EEA. Where they do, transfers rely on Standard Contractual Clauses or another mechanism permitted under Chapter V of the GDPR.
You can request information about the relevant transfer mechanism by contacting us.
| Data | Retention |
|---|---|
| Account and workspace data | For as long as your account is active |
| Conversation data | For the duration of the workspace's subscription, or a shorter period our customer configures |
| Cross-session memory | Until the configured expiry, or until deletion is requested |
| Closed / deleted workspaces | Retained in read-only form for 30 days, then permanently deleted |
| Invoices, payment records and tax documents | For the period required by applicable Serbian accounting and tax law |
| Security and access logs | For as long as necessary for the purpose, and consistent with our security and legal obligations |
| Support correspondence | For as long as necessary for the purpose, and consistent with our security and legal obligations |
After the applicable period we delete or irreversibly anonymise the data, except where we must keep it to meet a legal obligation or to defend a legal claim.
If we are the controller (section 2(a)), you have the right to:
To exercise any of these, email us at office@promptly-assistant.com. We will respond within one month as required by the GDPR, and in any event no later than the applicable statutory deadline. We may ask you to verify your identity before we act.
If we are the processor (section 2(b)), please direct your request to the website operator who runs the assistant. We will assist them in responding.
If you believe we have handled your personal data unlawfully, please tell us first — we would rather fix it directly. You also have the right to lodge a complaint with a supervisory authority: you may lodge it with the Serbian Commissioner for Information of Public Importance and Personal Data Protection, or with your local EEA supervisory authority.
We take security seriously and apply measures appropriate to the risk, including:
No system can be guaranteed absolutely secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority and affected customers as required by law and without undue delay.
If you believe you have found a security vulnerability in Promptly, we want to hear from you. Report it to office@promptly-assistant.com with a description, reproduction steps and your environment, and please give us reasonable time to investigate before disclosing publicly.
Promptly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy. For material changes we will notify customers by email or through the service before they take effect. The "Last updated" date above always reflects the current version.
| Email — privacy requests, DPA requests, data subject rights, security reports | office@promptly-assistant.com |
|---|---|
| Telephone | +381 21 301 9244 |
| Post | Lilly021 d.o.o., Bulevar oslobođenja 30A, 21000 Novi Sad, Serbia |
We aim to respond within 2 business days, and in any case within the deadlines the GDPR sets for data subject requests.
See also our Terms of Service and Refund Policy.