Privacy policy
What perly collects, why, where it is kept, and how to have it deleted.
The short version
- perly reads only the sources you connect, and only as far as you allow.
- Your data belongs to your company. We never sell it or use it for advertising.
- It is never used to train general AI models, and the model providers we use neither keep it nor train on it.
- Each company gets its own deployment and database, hosted in Europe.
- Ask us to delete your data and it is gone within 7 days.
01
Who we are
perly is operated by Genesis Software Group (“we”, “us”), Dag Hammarskjölds Allé 5, 1th, 2100 Copenhagen, Denmark. We are the processor of the data held in a customer’s workspace, and the controller of the account data we need to run the service. Questions about this policy go to contact@genesissoftware.io.
02
What perly collects, and why
Account data.
Your name and email address, from the account you sign in with. We use them to identify you, to find the workspaces you are a member of, and to tell you about the service.
Content from connected sources.
Only from the sources you connect yourself, and only what the access you grant allows:
- Gmail: reading messages and attachments; writing drafts, and sending mail only where your workspace allows it.
- Google Calendar: reading events; creating and updating events when you ask perly to.
- Google Drive: reading the folders you choose; creating files perly makes for you. It never changes or deletes files it did not create.
- Slack: channels and messages the connecting person can see.
- Files you add yourself: documents, chat exports and meeting recordings you upload.
- Other sources your workspace connects, such as an issue tracker or a CRM: only what the connecting person grants, used for the same purpose.
We use that content for one purpose: to build your workspace’s graph of people, projects and commitments, and to run agents for that workspace. Every feature reads only what it needs for that.
Service data.
Logs of requests and errors, without message content, which we keep to operate and secure the service.
Usage data.
Which pages of this website are visited, and which parts of perly are used and how often, such as the screens opened and the questions asked of perly. It never includes the content of your workspace: not your messages, documents or the words of a question. On this website it is counted without cookies and without identifying you. In perly it is linked to your account, so we can see which parts of the product people rely on and improve them.
Careers updates.
If you leave your email on our careers page, we use it only to tell you when a role opens. We delete it when you ask, or when you unsubscribe from one of those emails.
03
Google user data
perly’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data received from Google:
- is used only to provide the features you enable in your workspace;
- is never sold;
- is never used for advertising;
- is never used to train generalised AI or machine-learning models;
- is read by a person at Genesis Software Group only with your consent, or where necessary for security, to comply with the law, or as part of an internal operation on aggregated, anonymised data.
Connecting a Google account is optional and done per person. You can revoke it at any time from your Google account’s permissions page, or by disconnecting the source in perly.
04
Where it is stored
Each customer has its own deployment and its own database; a workspace’s data is never mixed with another customer’s. Data is stored in Europe, with Amazon Web Services, and is encrypted in transit and at rest.
05
Retention and deletion
- Disconnecting a source stops perly reading it straight away. Content already in the workspace stays until it is deleted.
- Deleting a workspace deletes its database and everything derived from it within 7 days, after a period in which the customer may export it.
- You can ask for the data perly holds about you to be deleted at any time, by writing to us or to your workspace’s owner. It is deleted within 7 days.
- Service logs are kept for 90 days.
06
Security
Access to a workspace is granted by its owner and checked on every request. Tokens for connected sources are stored encrypted and are used only by that workspace’s own deployment. Our staff have no standing access to workspace content, and any access for support or security is recorded.
07
Subprocessors
We use these third parties to provide the service, under contracts that bind them to this policy:
- Amazon Web Services, in Europe: hosting and storage of each deployment.
- Model providers, to run agents. Prompts contain the minimum of workspace content needed for the task, and under our agreements a provider does not retain them or train on them.
- PostHog, in Europe: the usage data above, for product analytics. It never receives workspace content.
We will update this list before adding to it.
08
Your rights
You can ask to see the data we hold about you, to have it corrected or deleted, to receive a copy of it, or to object to how it is processed. Write to us and we answer within 30 days; deletion requests are carried out within 7. If we process your data on a customer’s behalf, we may refer the request to that customer. You can also complain to the Danish Data Protection Agency (Datatilsynet) or your local authority.
09
Changes
We may change this policy. A change that affects how your data is used is announced in the workspace and by email before it takes effect, and the date at the top says which version this is.
10
Contact
Genesis Software Group, Dag Hammarskjölds Allé 5, 1th, 2100 Copenhagen, Denmark. Questions about this policy go to contact@genesissoftware.io.