Privacy Policy
Last updated: 29 May 2026
This policy explains how Tellaris collects and handles personal data when you visit tellaris.ai or contact us through this site. It covers the marketing website only. When Tellaris processes traffic data on behalf of an operator under a deployment, that processing is governed by a separate data processing agreement, not this policy. Request our DPA.
1. Who we are
Tellaris is the data controller for the personal data described here. We are incorporated in Belgium and based in Waterloo. For any privacy question, or to exercise your rights, email [email protected].
2. What we collect, and why
Demo and contact requests
When you submit the contact form, we collect your work email, company name, and the topic you selected. We use this only to reply and arrange the conversation you asked for.
- Purpose: responding to your enquiry and taking steps at your request prior to any agreement.
- Legal basis (GDPR Art. 6): steps prior to entering a contract (Art. 6(1)(b)) and our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
Analytics
We use Umami, a privacy-preserving analytics tool operated for us by Flowful AI, a Belgian company, on Hetzner servers in the EU. It sets no cookies and does not track you across other sites. It records only aggregated metrics such as page views, referrer, approximate (country-level) location, and device type, without storing your full IP address.
- Purpose: measuring and improving the site.
- Legal basis: our legitimate interest in understanding site usage (Art. 6(1)(f)).
Technical logs
Our hosting and our content-delivery / security proxy keep short-lived technical logs (such as IP address, timestamp, and user agent) to deliver the site, keep it available, and protect it against abuse.
- Legal basis: our legitimate interest in security and reliable operation (Art. 6(1)(f)).
3. Cookies
This site does not use advertising or cross-site tracking cookies. Our analytics are cookieless. We may use a small number of strictly necessary, technical cookies where required to serve the site securely.
4. Who we share data with
We do not sell your data and we do not share it with data brokers. We rely on a small number of processors who act on our instructions:
- Resend (United States) — delivers the email generated by the contact form to us, under Standard Contractual Clauses.
- Cloudflare — content delivery and protection of the site.
- Hetzner (European Union) — hosts the server that serves the site.
- Flowful AI (Belgium) — operates our cookieless analytics (Umami) on our behalf, on Hetzner servers in the European Union.
We may also disclose data where we are legally required to, or to establish, exercise, or defend legal claims.
5. International transfers
The website and our analytics are hosted on Hetzner servers within the European Union. The main transfer outside the European Economic Area is Resend, which delivers our contact-form email and is based in the United States; that transfer is covered by the European Commission's Standard Contractual Clauses. Where any other data leaves the EEA, the transfer is likewise covered by an adequacy decision or by appropriate safeguards such as the Standard Contractual Clauses.
6. How long we keep it
We keep contact and demo enquiries for up to 24 months after our last contact with you, unless a longer period is needed to manage an ongoing relationship or to meet a legal obligation, after which we delete or anonymise them. Analytics are held only in aggregate. Technical logs are kept only briefly.
7. Your rights
Under the GDPR you can:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing;
- receive your data in a portable form;
- withdraw consent at any time, where processing relies on consent.
To exercise any of these, email [email protected]. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be.
8. Security
The site is served over TLS, and we apply the security practices described on our security overview.
9. Changes to this policy
We may update this policy from time to time. The current version is always the one published here, with the date shown at the top.