Privacy Policy
Last updated: June 28, 2026
This Privacy Policy explains how Cerell (“we”, “us”) collects and processes personal data when you use our website, create a workspace, or embed our scripts on your site. For visitor data collected through your embed, you are the data controller and Cerell acts as your data processor under GDPR.
1. Who we are
Cerell operates the website conversion platform at cerell.eu. Privacy contact: privacy@cerell.eu.
2. Controller and processor roles
Cerell as controller: We process account data (name, email, billing) for customers who register a workspace on Cerell.
You as controller: When you install the Cerell embed, you decide what visitor data is collected (page views, leads, chat). You must provide your own privacy notice and lawful basis to your site visitors.
Cerell as processor: We store and process visitor, lead, and chat data on your instructions, as described in your workspace settings and this policy.
3. Data we process
Account data: email, password (hashed), workspace name, role, billing metadata via Stripe.
Visitor & lead data (on your behalf): opaque visitor IDs, page paths, device/browser, referrer, UTM parameters, scroll/click events, form submissions (email, phone, consent text/timestamp), chat messages, and optional enrichment results you configure.
Technical logs: IP addresses for rate limiting and abuse prevention; error reports via Sentry (no intentional storage of chat content in error logs).
4. Legal bases (GDPR)
We process account and billing data under contract (Art. 6(1)(b)) to provide the service.
We process visitor data as your processor under contract and your documented instructions.
We may process data under legitimate interests (Art. 6(1)(f)) for security, fraud prevention, and service improvement, balanced against your rights.
5. How we use data
Provide embed tracking, lead capture, AI chat, Slack handoff, intel dashboards, and CRM exports you configure.
Send transactional email (password reset, service notices) via Resend.
We do not sell personal data. We do not use visitor chat content to train public models.
6. Retention
Account data is kept while your workspace is active and as required for legal obligations after deletion.
Visitor intel retention defaults to 30 days per workspace (configurable within plan limits). Knowledge base chunks persist until you delete them or delete the workspace.
You can export or delete workspace data at any time from Dashboard → Privacy & data.
7. Subprocessors
We use vetted third parties to run the platform. See our Subprocessor list for names, purposes, and locations.
8. International transfers
Primary hosting and database regions are in the EU. Where subprocessors process data outside the EEA, we rely on Standard Contractual Clauses or equivalent safeguards.
9. Your rights
Depending on your role and jurisdiction, you may have rights to access, rectify, erase, restrict, port, or object to processing, and to lodge a complaint with a supervisory authority.
Workspace owners can export all workspace data (JSON) and delete the workspace from the dashboard. For requests about your Cerell account, email privacy@cerell.eu.
If you are a visitor to a customer website using Cerell, contact that website owner first; they are the controller for your data.
10. Security
We encrypt secrets at rest, use HTTPS, enforce origin allowlists on embed tokens, rate-limit public APIs, and apply SSRF protections on outbound webhooks. Access to production systems is restricted.
11. Changes
We may update this policy. Material changes will be posted on this page with an updated date. Continued use after changes constitutes acceptance where permitted by law.
12. Contact
Questions: privacy@cerell.eu. Support: hello@cerell.eu.