Privacy Policy
Last updated: 24 April 2026
This Privacy Policy explains how Jarolis Ltd ("Jarolis", "we", "us", "our") collects, uses, and protects personal data when you visit jarolis.com, join our waitlist, use our AI chat assistant, or otherwise interact with our website and services (together, the "Services").
This policy is written to comply with the UK GDPR, EU GDPR, the Swiss Federal Act on Data Protection (nFADP), the Turkish Personal Data Protection Law (KVKK), the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA, and other applicable data protection laws. Where a jurisdiction provides additional rights beyond those described here, those rights are addressed in the jurisdictional addendums at the end of this document.
The English version of this Privacy Policy is the authoritative legal text. Translations in other languages are provided as a courtesy. In case of any discrepancy between the English version and a translation, the English version prevails.
1. Who we are
Jarolis Ltd is a private limited company incorporated in England and Wales.
- Company number: 17077504 (Companies House)
- Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
- Privacy contact: privacy@jarolis.com
- General contact: hello@jarolis.com
Jarolis acts as the data controller for the personal data processed through the Services. We are currently completing registration with the UK Information Commissioner's Office (ICO).
2. What data we collect
2.1 Data you provide directly
- Email address — when you join our Kickstarter waitlist or submit a contact form.
- Messages you send — when you interact with our AI chat assistant, we process the content of your conversation.
- Optional email in chat — if you provide an email during a chat session to receive a follow-up response.
2.2 Data collected automatically
- Technical data — IP address, approximate country (via Cloudflare), device type, browser, operating system, and referring URL.
- Usage data — pages visited, time on page, scroll depth, and language preference. Collected by our privacy-friendly, cookie-free analytics tool (Umami).
- Marketing attribution — UTM parameters (source, campaign, medium, etc.) from URLs you click to reach our site.
- Chat session metadata — when using the AI chat assistant, we log session ID, timestamp, message count, language, and approximate country of origin.
2.3 Data collected only after your consent
The following data is collected only if you accept non-essential cookies through our consent banner (CookieBot):
- Google Analytics 4 (GA4) — traffic patterns, conversion tracking.
- Meta (Facebook/Instagram) Pixel — ad attribution and remarketing.
- TikTok Pixel — ad attribution and audience building.
You can withdraw your consent at any time by clicking the cookie settings link in our footer or the CookieBot icon.
3. How we use your data
We use your personal data for the following purposes:
- Waitlist management — to send you updates about our Kickstarter launch, product availability, and early-bird offers.
- AI chat support — to answer product questions in real time and optionally follow up via email.
- Analytics and product improvement — to understand how visitors use our site and improve user experience.
- Marketing attribution — to measure the effectiveness of our marketing campaigns and advertising.
- Security and abuse prevention — to detect fraud, prompt injection, spam, and abusive behaviour.
- Legal compliance — to comply with applicable laws, regulations, and lawful requests from authorities.
4. Legal bases (GDPR Article 6)
| Purpose | Legal basis |
|---|---|
| Waitlist email signup and product update emails | Consent (Art. 6(1)(a)) |
| AI chat responses and optional follow-up | Consent and performance of our pre-contractual relationship (Art. 6(1)(a), (b)) |
| Cookie-free analytics (Umami) | Legitimate interest (Art. 6(1)(f)) — understanding site performance |
| GA4, Meta Pixel, TikTok Pixel | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, abuse detection | Legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
5. Who we share your data with
We share personal data only with the following categories of recipients, and only to the extent necessary for them to perform their services on our behalf:
- Brevo (Sendinblue SAS, France) — email service provider for waitlist and transactional emails. GDPR-compliant, hosted in the EU.
- Cloudflare, Inc. (USA) — website hosting, content delivery, security, and request routing.
- Anthropic, PBC (USA) — provider of the AI model (Claude) that powers our chat assistant. Message content is sent to Anthropic for generating responses.
- Umami Analytics — self-hosted, cookie-free analytics.
- Cookiebot (Cybot A/S, Denmark) — consent management platform.
- Google LLC (USA) — Google Analytics 4, after consent.
- Meta Platforms, Inc. (USA) — Meta Pixel, after consent.
- TikTok Technology Ltd (Ireland) and ByteDance Ltd — TikTok Pixel, after consent.
We do not sell your personal data. We do not share your personal data with third parties for their own marketing purposes.
We may disclose personal data if required by law, court order, or lawful government request, or to protect our legal rights, property, or safety.
6. International data transfers
Some of our service providers are located outside your country of residence (e.g., the United States). When we transfer personal data outside the UK, EU/EEA, Switzerland, or Turkey, we rely on one or more of the following safeguards:
- EU Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreement (IDTA)
- EU-US Data Privacy Framework (DPF) certification of the recipient (where applicable)
- Adequacy decisions recognised by the UK or EU Commission
You can request a copy of the specific safeguards in place for a given transfer by contacting us at privacy@jarolis.com.
7. How long we keep your data
| Data type | Retention |
|---|---|
| Waitlist email address | Until you unsubscribe, with automatic deletion after 3 years of inactivity. |
| AI chat conversation logs | Up to 24 months, or earlier upon your erasure request. |
| Cookie-free analytics data (Umami) | 24 months, aggregated and non-identifying. |
| Marketing analytics after consent (GA4, Meta, TikTok) | According to each provider's retention policies; generally up to 14 months. |
| Server logs and security records | Up to 12 months. |
After the retention period, personal data is deleted or anonymised so it can no longer be linked to you.
8. Your rights
Under the UK GDPR, EU GDPR, and equivalent laws, you have the following rights in relation to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — to request deletion of your data.
- Right to restriction of processing — to limit how we use your data in specific circumstances.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object — to object to processing based on legitimate interest, including profiling and direct marketing.
- Right to withdraw consent — at any time, where processing is based on consent.
- Right not to be subject to solely automated decisions — we do not make decisions with legal or similarly significant effects about you using solely automated means.
- Right to lodge a complaint — with your local supervisory authority.
To exercise any of these rights, contact us at privacy@jarolis.com. We will respond within one month as required by law. There is no charge for exercising your rights, and we will not discriminate against you for doing so.
9. Cookies and similar technologies
We use cookies and similar technologies to operate the Services, measure performance, and — if you consent — to support advertising and analytics.
For a detailed list of cookies, their purposes, and how to manage your preferences, see our Cookie Policy.
10. Security
We use industry-standard security measures to protect your personal data, including:
- Encryption in transit (TLS 1.2+) for all data exchanged between your device and our servers.
- Encryption at rest for data stored in our databases.
- Access controls, secret rotation, and principle of least privilege for our staff and systems.
- Regular security review and dependency auditing.
- Rate limiting and prompt-injection defences on our AI chat assistant.
No method of transmission or storage is 100% secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant supervisory authorities in accordance with applicable law.
11. Children's privacy
The Services are not directed at children under the age of 16 (or the minimum age to consent to processing of personal data under applicable local law). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@jarolis.com and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify waitlist subscribers by email. Please review this policy periodically.
13. How to contact us
If you have any questions, concerns, or requests regarding this policy or your personal data:
- Privacy email: privacy@jarolis.com
- General email: hello@jarolis.com
- Post: Jarolis Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
14. Jurisdictional addendums
The following addendums apply to residents of specific jurisdictions. Rights and obligations described here are in addition to those set out in the main policy above.
14.1 United Kingdom residents
Personal data of UK residents is processed under the UK GDPR and the Data Protection Act 2018. The supervisory authority is the Information Commissioner's Office (ICO).
You have the right to lodge a complaint with the ICO: ico.org.uk/make-a-complaint — Tel: 0303 123 1113.
Jarolis Ltd is in the process of registering with the ICO as a data controller.
14.2 European Union / EEA residents
Personal data of residents in the EU/EEA is processed under the EU GDPR. If you are in Norway, Iceland, or Liechtenstein, the GDPR applies through the EEA Agreement.
You have the right to lodge a complaint with the supervisory authority of your country of residence or usual workplace. A list of EU/EEA supervisory authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en.
Because Jarolis Ltd is established outside the EU, we may designate an EU representative under GDPR Article 27 when our processing activities cross the relevant thresholds. At present our processing of EU personal data is limited to non-sensitive waitlist and analytics data; should this change, we will appoint and publish the details of an EU representative.
14.3 Swiss residents
Personal data of Swiss residents is processed in accordance with the Swiss Federal Act on Data Protection (nFADP), effective 1 September 2023. The supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
You have rights equivalent to those described in Section 8 of this policy, including the right to access, correct, and delete your personal data, and to object to its processing. To exercise these rights, contact privacy@jarolis.com.
14.4 Turkish residents (KVKK)
For residents of Türkiye, personal data is processed in accordance with the Turkish Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu, Law No. 6698, "KVKK").
Local contact for KVKK matters:
- Enes Levent, Director, Jarolis Ltd
- IzQ İzmir İş Geliştirme Merkezi, Gaziemir, İzmir, Türkiye
- Email: privacy@jarolis.com
Under KVKK Article 11, you have the right to learn whether your personal data is processed, request information about processing, learn its purpose and whether it is used consistent with that purpose, identify third parties to whom data has been transferred, request correction or deletion, and seek compensation for damages arising from unlawful processing.
You may submit requests in Turkish or English. We will respond within 30 days as required by KVKK. You also have the right to apply to the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) at kvkk.gov.tr.
14.5 California residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:
- Right to know the categories and specific pieces of personal information we collect, use, and share.
- Right to delete personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising. We do not sell personal information for money. If you withhold consent for advertising cookies, we will not "share" your personal information under the CPRA definition.
- Right to limit use of sensitive personal information.
- Right to non-discrimination for exercising any of these rights.
To exercise any of these rights, contact privacy@jarolis.com. We will verify your request using reasonable means (e.g., confirming the email address on file).
14.6 Canadian residents
Personal data of Canadian residents is processed in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA). Quebec residents have additional rights under An Act to modernize legislative provisions as regards the protection of personal information (Law 25).
You have the right to access your personal data, request corrections, and withdraw consent to its collection, use, or disclosure. For Quebec residents, you also have the right to data portability and to be informed of automated decision-making. To exercise these rights, contact privacy@jarolis.com.
You may also file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for Quebec residents, the Commission d'accès à l'information (cai.gouv.qc.ca).
14.7 Other jurisdictions
If you reside in a jurisdiction not listed above, you may still have rights under your local law. We apply GDPR-equivalent standards globally as our baseline. If you would like to exercise a right specific to your jurisdiction, please contact privacy@jarolis.com and we will work with you in good faith.