Privacy Policy
Last updated: July 29, 2026
Effective: May 16, 2022
Your product data stays in the EU.
Customer Data and product usage data are stored in Microsoft Azure data centers, pinned to EU locations. One exception, outside the product: with your consent, our public website uses marketing cookies from advertising partners who may process data outside the EU — never inside the product. See "Cookies & tracking" below.
We don't sell your data.
Not to advertisers, not to third parties, not ever. With your consent, our website shares limited visitor data with advertising partners so we can measure our own campaigns — details in our Cookie Policy.
Your employer controls workspace data.
We process it on their behalf under strict terms.
Zero Trust architecture.
Encrypted in transit and at rest, SSO via Microsoft 365, audit-logged access.
You can delete your data.
Request access, correction, or deletion anytime at privacy@ervy.ai.
Scope & applicability
This Privacy Policy applies to Ervy's online workplace learning tools and platform (the "Services"), the ervy.ai website (the "Website"), and other interactions you may have with us. Ervy is owned and operated by WeAreDots, SIA.
This policy does not apply to third-party applications that integrate with our Services, or any other third-party products or businesses. A separate Customer Agreement governs the delivery and use of the Services, including the processing of content submitted through your workspace.
If you don't agree with this policy, please do not access or use the Services, Website, or any other aspect of our business.
Data controller & processor
Your organization (the "Customer" — typically your employer) is the controller of Customer Data. Ervy acts as the processor of Customer Data and the controller of Other Information, such as usage analytics and account details.
For the Website (www.ervy.ai): WeAreDots, SIA is the data controller for personal data collected from Website visitors, including data collected through cookies and similar technologies described in our Cookie Policy. For event data collected and transmitted through the Meta Pixel and the LinkedIn Insight Tag, responsibilities are divided as follows. We are responsible for obtaining your consent before these tags load, for telling you what they collect, and for handling your requests about that collection. Meta Platforms Ireland Limited and LinkedIn Ireland Unlimited Company are each responsible for what they do with the data afterwards, including any use for their own purposes, and for responding to your requests about that later use. This shared responsibility for the collection stage is what the GDPR calls joint controllership (Art. 26); the essence of each arrangement is available from Meta and LinkedIn (links in our Cookie Policy). You may contact either us or the relevant partner to exercise your rights.
For the Services (web.ervy.ai): no advertising or marketing trackers operate within the Services, including the sign-in page. Data about your use of the product is never shared with advertising partners.
In practice, this means your employer decides what data goes into Ervy, and we process it strictly according to their instructions and our Customer Agreement.
Information we collect
We collect and receive two categories of information:
Customer Data — content submitted to Ervy by your organization or its authorized users when using the Services (documents, learning content, quiz responses, etc.).
Other Information — data we collect to operate and improve the service:
Account info:
email address, domain, billing details
Usage metadata:
features used, content viewed, interaction patterns
Device & log data:
IP address, browser type, OS, timestamps
Location data:
approximate location derived from IP or business address
Cookies:
Cookies & marketing data (Website visitors only, with your consent): cookie identifiers, advertising click identifiers (e.g. gclid, msclkid, li_fat_id, fbclid), pages visited on the Website, and marketing conversion events such as demo bookings or trial sign-ups. See our Cookie Policy for the full list of technologies, providers and durations.
Third-party integrations:
data shared when you enable connected services
How we use your information
We collect and receive two categories of information:
Customer Data is used strictly according to your organization's instructions and the Customer Agreement.
Other Information is used to operate, maintain, and improve our Services — including delivering the product, responding to support requests, developing new features, sending service communications, managing billing, and investigating security issues.
Marketing (Website only): with your consent, we use cookies and similar technologies from advertising partners to measure the performance of our advertising campaigns, attribute sign-ups and demo requests to those campaigns, and build audiences for advertising on Google, Microsoft/Bing, LinkedIn, Facebook and Instagram. We only advertise our own services. You can withdraw consent at any time via the "Cookie settings" link on our Website.
Legal bases for processing
Where the GDPR applies, we rely on the following legal bases: Performance of a contract (Art. 6(1)(b)) — providing the Services, managing accounts and billing. Legitimate interests (Art. 6(1)(f)) — securing and improving the Services, preventing abuse, and service analytics; you may object at any time. Consent (Art. 6(1)(a)) — analytics and marketing cookies on the Website and marketing communications; you may withdraw consent at any time without affecting prior processing. Legal obligation (Art. 6(1)(c)) — accounting, tax and other statutory requirements.
Where we process Customer Data as a processor, the legal basis is determined by your organization as controller.
Sharing & disclosure
We share information only in these circumstances:
Customer instructions:
as directed by your organization's agreement with us
Within your workspace:
authorized users may see profile information
Service providers:
trusted third parties that help us operate (under strict agreements)
Advertising partners (Website only, with your consent):
Google Ireland Limited, Microsoft Ireland Operations Limited, Meta Platforms Ireland Limited and LinkedIn Ireland Unlimited Company receive cookie and event data from our Website to help us measure and deliver our advertising. They do not receive Customer Data or any data from inside the product.
Legal requirements:
when required by law, regulation, or legal process
Business changes:
in the event of a merger, acquisition, or sale
With your consent:
when you explicitly agree to sharing
International data transfers
Customer Data and product usage data are stored and processed in Microsoft Azure data centers in the European Union and are not transferred outside the EU/EEA.
If you consent to marketing cookies on our Website, the advertising partners listed in our Cookie Policy may transfer the resulting data (cookie identifiers, event data, IP address) to their parent companies in the United States. Each of these companies — Google LLC, Microsoft Corporation, Meta Platforms, Inc. and LinkedIn Corporation — is certified under the EU–U.S. Data Privacy Framework, which the European Commission has recognised as providing adequate protection (Art. 45 GDPR). Where the Framework does not apply, transfers are protected by the European Commission's Standard Contractual Clauses with supplementary measures.
You can prevent these transfers entirely by declining marketing cookies.
Data retention
Customer Data is retained according to your organization's instructions and agreement terms.
Other Information is retained for no longer than 2 years, unless a longer period is required by law. When we no longer need your data, we delete or anonymize it. If deletion isn't immediately possible (e.g., backup archives), we isolate the data and protect it until deletion is feasible.
Cookies & tracking
Our Website uses cookies and similar technologies in three categories: strictly necessary (always active), analytics, and marketing. Analytics and marketing cookies are set only if you opt in through the cookie banner shown on your first visit. Marketing cookies are used only on our public Website — never inside the Ervy product.
You can change your choices or withdraw consent at any time via the "Cookie settings" link in the Website footer. Withdrawing consent is as easy as giving it and does not affect your use of the Website. You can also delete or block cookies in your browser settings.
The full list of cookies, their providers, purposes, durations and the data they transfer is in our Cookie Policy.
We do not currently respond to Do-Not-Track (DNT) browser signals, as no uniform standard has been established.
Security measures
All data is stored in Microsoft Azure data centers located in the EU. We follow Zero Trust architecture principles across our infrastructure.
Authentication is handled via Microsoft 365 SSO — no additional passwords required. All production access is logged, audited, and restricted. Development environments are fully separated from production data.
Your privacy rights
Depending on your jurisdiction, you may have the right to:
• Request access to and obtain a copy of your personal data
• Request correction or deletion of your data
• Restrict or object to processing
• Data portability
• Withdraw consent at any time — for cookies, use the "Cookie settings" link in the Website footer; for marketing emails, use the unsubscribe link; for anything else, email privacy@ervy.ai
To exercise any of these rights, email privacy@ervy.ai. We respond within 30 days. If you're in the EEA and believe we're processing your data unlawfully, you can also contact your local supervisory authority.
Data breach policy
In the event of a data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (unless it poses no risk to individuals). We will also notify affected users directly when we believe there is a risk of serious harm.
Children's privacy
We do not knowingly collect data from or market to anyone under 18 years of age. If we discover that a minor's data has been collected, we will deactivate the account and delete the data promptly.
Policy updates
We may update this policy from time to time. Material changes will be communicated via a prominent notice on our website or a direct notification. The "Last updated" date at the top of this page always reflects the most recent revision.
Contact us
WeAreDots, SIA
Kronvalda Boulevard 3-5
Riga, LV-1010, Latvia
E-mail: privacy@ervy.ai
Phone: +371 67509912



