Privacy Policy
Last updated: 27 July 2026
1. Who We Are
Ecolyxis is an AI-powered chatbot service operated by Ecolyxis. Ecolyxis is the data controller responsible for your personal data under the UK GDPR.
For all privacy and data protection enquiries, including data subject access requests (DSARs), please contact us or email ashley@ecolyxis.co.uk.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. You may also contact your local data protection authority if you are outside the UK.
2. What Data We Collect & Why
2.1 Account Information
- Data: email address, display name, hashed password.
- Purpose: to create and manage your account and authenticate you.
- Legal basis: performance of a contract (Art. 6(1)(b) UK GDPR) — you cannot use Ecolyxis without an account. Providing this data is a contractual requirement; if you do not provide it, we cannot provide the service.
- Retention: until you delete your account. Passwords are stored only as one-way hashes (bcrypt) and can never be recovered in plain text.
2.2 Chat Messages & AI Responses
- Data: the prompts you send, the AI-generated responses, and any images you upload or generate.
- Purpose: to process your requests through our AI models and maintain your conversation history.
- Legal basis: performance of a contract (Art. 6(1)(b)).
- Retention:
- Free-tier users: messages older than 24 hours are automatically and permanently deleted on an hourly cycle.
- Premium users: messages are retained until you delete the conversation or your account.
- Third-party sharing: none. All AI inference runs on our own server infrastructure. Your messages are never transmitted to any external AI provider or third-party API.
2.3 Usage & Analytics Data
- Data: feature usage counts, token consumption, and performance metrics. We do not use third-party analytics services (no Google Analytics, no external trackers).
- Purpose: to monitor service health, allocate computational resources, and improve performance.
- Legal basis: legitimate interests (Art. 6(1)(f)) — operating and maintaining a reliable service.
- Retention: individual usage records retained for up to 12 months; aggregated and anonymised statistics retained indefinitely.
2.4 Technical & Security Logs
- Data: IP address, browser type, device information, login timestamps, and rate-limiting data.
- Purpose: authentication, brute-force protection, fraud prevention, security auditing, and rate limiting.
- Legal basis: legitimate interests (Art. 6(1)(f)) — protecting our service and our users from abuse.
- Retention: rate-limit data is purged automatically as it expires. Server access logs are retained for up to 90 days for security purposes, then permanently deleted.
3. Automated Decision-Making & AI Processing
Ecolyxis uses AI models to generate responses to your prompts. This processing is an integral part of the conversational service you have requested. It does not constitute automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 UK GDPR — the AI generates conversational responses for your use, and you are always free to disregard them.
Our AI models do not evaluate or make decisions about you personally. They process only the text and images you provide in a given conversation to generate a response.
4. Data Sharing & Recipients
We do not sell, trade, rent, or share your personal data with third parties. We may disclose data only:
- When required to do so by law or valid legal process.
- To protect our legal rights, safety, or property.
We do not use any external data processors that would transfer your data outside our infrastructure. All data remains on servers within our direct control. There are no international data transfers.
5. Data Storage & Security
Your data is stored on our own servers. Technical and organisational security measures include:
- TLS encryption (HTTPS) for all connections.
- Password hashing using bcrypt — passwords cannot be recovered in plain text.
- Session cookie hardening — HttpOnly, SameSite=Lax, Secure flags.
- CSRF protection on all forms.
- Rate limiting and brute-force protection on authentication endpoints.
- Strict access controls and role-based authentication.
- Automated data deletion for expired content.
6. Your Data Protection Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right to be informed (Art. 13–14): you are reading it — this policy.
- Right of access (Art. 15): you can request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): you can correct inaccurate or incomplete data at any time via your account settings.
- Right to erasure (Art. 17): you can delete your account and all associated data at any time via Settings → Delete Account, or by contacting us.
- Right to restrict processing (Art. 18): you can ask us to limit how we use your data in certain circumstances (e.g., while a data accuracy dispute is resolved).
- Right to data portability (Art. 20): you can receive the personal data you have provided to us in a structured, commonly used, machine-readable format (JSON or CSV). To request this, please contact us.
- Right to object (Art. 21): you can object to processing based on legitimate interests (e.g., analytics, security logs). We will stop unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): where any processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
We will respond to all requests within one month, as required by Article 12(3) UK GDPR. This may be extended by two further months for complex or numerous requests, in which case we will inform you within the first month.
To exercise any of these rights, please contact us or email ashley@ecolyxis.co.uk.
7. Cookies
We use only strictly necessary cookies for authentication and session management. These are essential for the service to function and are exempt from consent requirements under regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR).
- Session cookie: HttpOnly, SameSite=Lax, transmitted only over HTTPS (Secure flag).
- No advertising, tracking, or third-party analytics cookies are set at any time.
8. Personal Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, as required by Article 33 UK GDPR. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users directly without undue delay (Art. 34).
9. Sustainability Commitment
Ecolyxis is designed to minimise environmental impact. Our infrastructure runs on energy-efficient hardware, and we continuously optimise our AI models to reduce computational requirements and energy consumption.
10. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top will always reflect the most recent revision. Where changes materially affect your rights or how we process your data, we will notify you through the service or by email.