1. Who We Are
Intuitly is an AI-powered digital sales assistant platform, providing intelligent shopping assistance tools to ecommerce businesses and their customers. We are committed to protecting your privacy and ensuring transparency around how we use your personal data.
2. What Data We Collect
We may collect and process the following types of personal data, depending on how you interact with the platform:
| Category | Examples |
|---|---|
| Account Data | Name, email address, company name, role |
| Chat Interactions | Questions submitted via the AI assistant |
| Product Data | Data from uploaded product catalogues and inventory |
| Usage Analytics | Timestamps, feature usage, clickstream data |
| Support Correspondence | Email or platform-based messages |
We do not collect sensitive personal data unless explicitly provided by the client.
2.1 Data Processing Roles
Intuitly acts as a data processor on behalf of our client organizations (ecommerce stores), who are the data controllers. This means:
- Your ecommerce store determines what data is collected and how it's used
- Intuitly processes this data according to the store's instructions
- The store remains responsible for responding to privacy rights requests from their customers
- We support our clients in fulfilling their GDPR obligations
For end customers: Contact the ecommerce store directly for data-related requests.
For client administrators: Contact privacy@intuitly.co for technical assistance.
3. How and Why We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Provide and improve our AI sales assistant | Performance of a contract |
| Personalise product recommendations via AI/LLM | Legitimate interest / contract |
| Support and service operations | Legitimate interest |
| Usage analysis and performance monitoring | Legitimate interest |
| Legal compliance | Legal obligation |
4. Use of Large Language Models (LLMs)
To provide relevant and contextual shopping assistance, Intuitly uses enterprise-grade large language models (LLMs) within our secure cloud infrastructure. These models help power AI assistant responses to customer queries on your ecommerce store.
In some cases, we may include limited personal data in the form of:
- Customer name (if provided)
- Shopping preferences or browsing context
- The context of the query (e.g., "What size should I get for this jacket?")
This data is used solely to generate a more accurate and personalised response.
Safeguards
- No model training: Your data is never used to train AI models.
- No retention: Queries are processed statelessly — data is not stored beyond the processing cycle.
- Infrastructure controls: LLM processing occurs within our controlled EU-based cloud infrastructure with strict access controls and encryption.
- Minimal data sent: We only process the minimum data necessary to generate a useful response.
Product Catalogue Processing
When product catalogues are uploaded to Intuitly, they are:
- Processed within EU infrastructure
- Transformed through our LLM infrastructure for vectorization and product understanding
- Processed statelessly with no data retention beyond the processing cycle
- Stored as vector embeddings and product knowledge structures for fast retrieval
This processing enables accurate, context-aware product recommendations.
5. Data Sharing & Subprocessors
We may share data with trusted subprocessors under strict contractual and technical safeguards. Examples include:
| Vendor | Purpose | Location |
|---|---|---|
| AWS | Hosting & infrastructure | EU (multiple regions) |
| Pinecone | Vector database | EU (AWS eu-west-1) |
| Neo4j | Graph database for product relationships | European Union |
A full list of subprocessors is available upon request.
6. Data Retention
We retain data only as long as necessary to fulfill the purposes above or as legally required.
| Data Type | Retention Period |
|---|---|
| Account Data | Until deletion by user/admin |
| Uploaded product catalogues (original files) | Deleted immediately after processing |
| Vector embeddings | Duration of client contract |
| Product knowledge graphs | Duration of client contract |
| Interaction Logs | 12 months |
| Access & audit logs | 12 months |
You may request deletion at any time.
7. Your Rights
You have the right to:
- Access your data
- Request correction or deletion
- Object to processing
- Request data export (portability)
- Withdraw consent (where applicable)
Note: If you are a customer of an ecommerce store using Intuitly, the store acts as the data controller. To exercise your rights, please contact the store directly. They can use Intuitly's platform tools or contact us on your behalf.
If you are a client administrator, you can manage user rights directly through the platform or contact us at privacy@intuitly.co
8. International Transfers
When data is processed outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs)
- Vendor-specific enterprise safeguards
9. Security Measures
We implement robust security measures including:
- Encryption (at rest and in transit)
- Role-based access control and multi-factor authentication
- Comprehensive logging and monitoring
- Regular security testing and resilience planning
10. Cookies & Analytics
Our platform uses essential cookies for:
- User authentication and session management
- Basic functionality and security
We do not use advertising, tracking, or profiling cookies. You can manage cookie preferences in your browser settings, though disabling essential cookies may affect platform functionality.
11. Changes to This Policy
We may update this policy periodically. Material changes will be communicated at the next login or via email.
12. Contact
For questions or concerns about this privacy policy, contact: